Advisory ID:
ENSA-2026-1
CVSSv3:
9.8
Issue date:
2026-05-20
Updated on:
2026-05-20 (initial advisory)
CVE(s):
Pending CVE number
Synopsis:
A command injection flaw in the authentication code allows for unauthenticated remote code execution as the nobody user using a local internal interface. This issue affects IQ Gateway version D8.2.4264 through D8.3.5171.
1. Impacted product
Enphase IQ Gateway 8.2.4264 through 8.3.5171
2. Introduction
A security researcher is publishing an advisory identifying a vulnerability. An update is available to address this issue.
3. Summary
Description:
Enphase IQ Gateway 8.2.4264 through 8.3.5171 allows an unauthenticated attacker to execute a shell command by exploiting a command injection flaw in authentication code.
Known attack vectors:
A malicious actor may be able to exploit this opportunity if the IQ Gateway is modified to obtain a public IP address and connect to the public internet. Also, with local network access.
Resolution:
Upgrading the Enphase IQ Gateway embedded software to any version listed in the references section or to version 8.3.5562 or newer.
Workarounds:
Ensure that your IQ Gateway is not exposed to the public internet, as it is not needed to do so for typical functionality. A typical solution is to use an internet router to restrict HTTP/HTTPS traffic.
Additional documentation:
None.
Acknowledgments:
Enphase would like to thank the researcher Joseph Charles for reporting this issue.
Notes:
None.
4. References
IQ Gateway software release notes (8.3.5289)
IQ Gateway software release notes (8.3.5427)
IQ Gateway software release notes (8.3.5169)
IQ Gateway software release notes (8.3.5289) (EMEA)
IQ Gateway software release notes (8.3.5169) (EMEA)
5. Change log
2026-05-20 ENSA-2026-1: Initial security advisory.
6. Contact and information
cybersecurity@enphase.com
Enphase security advisories
Enphase vulnerability reporting
Enphase documentation center