CVE-2025-46414

8.1

EG4 Electronics · EG4 12kPV, 18kPV, Flex 21, Flex 18, 6000XP, 12000XP

EG4 Electronics products lack PIN attempt rate limiting, enabling brute-force attacks by unauthorized actors with a device serial number.

Executive summary

A critical authentication bypass vulnerability in multiple EG4 Electronics inverters allows unauthorized access via brute-force attacks on the device PIN.

Vulnerability

The vulnerability is an improper restriction of excessive authentication attempts (CWE-307) where the API fails to throttle PIN entry attempts. This allows an unauthenticated attacker who possesses a valid device serial number to systematically brute-force the PIN and gain administrative access.

Business impact

The ability for an unauthorized party to brute-force device authentication creates a significant risk of remote control over power management systems. Given the CVSS score of 8.1, this represents a high-severity threat that could lead to unauthorized system modification, potential equipment damage, or operational disruption.

Remediation

Immediate Action: Ensure all systems are updated to the current firmware levels, as this vulnerability was addressed via a server-side update implemented on April 6, 2025.

Proactive Monitoring: Review access logs for abnormal patterns of high-frequency authentication attempts originating from single or distributed IP addresses.

Compensating Controls: Implement network-level restrictions, such as firewall rules or VPN requirements, to limit exposure of the device API to the public internet.

Exploitation status

Public Exploit Available: exploit_available (unknown)

Analyst recommendation

Organizations utilizing affected EG4 Electronics hardware must verify that their systems have received the necessary server-side updates. Because this vulnerability allows for unauthorized access to critical infrastructure components, immediate verification of security posture and restricted network access for these devices is strongly advised to prevent potential exploitation.

Sources

Originally found and disclosed by Anthony Rose of BC Security reported these vulnerabilities to CISA., per the CVE Program record.