CVE-2024-21878

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This vulnerability is present in an internal script.This issue affects Envoy: from 4.x up to and including 8.x and is currently unpatched.

Credits

Wietse Boonstra of DIVD
Hidde Smit of DIVD
Frank Breedijk of DIVD
Max van der Horst of DIVD

References