
Remote Code Execution (RCE) proof of concept on a enphase solar inverter
CVE-2023-33869 is a command injection vulnerability affecting Enphase Envoy firmware version D7.0.88. This vulnerability allows an attacker to inject and execute arbitrary commands with root privileges on the affected device. The Enphase Envoy is a solar microinverter gateway device commonly deployed in residential and commercial solar energy systems, making this vulnerability particularly concerning for critical infrastructure and IoT environments.