A directory traversal vulnerability was discovered in Enphase Envoy R3.. via images/, include/, include/js, or include/css on TCP port 8888.
A weak password vulnerability was discovered in Enphase Envoy R3... One can login via TCP port 8888 with the admin password for the admin account.
XSS exists in Enphase Envoy R3.. via the profileName parameter to the /home URI on TCP port 8888.