CVE-2023-0808 - CVE House
Back to Database
Status published Low CVE-2023-0808

Deye/Revolt/Bosswerk Inverter Access Point Setting hard-coded password

Vulnerability Description

A vulnerability was found in Deye/Revolt/Bosswerk Inverter MW3_15U_5406_1.47/MW3_15U_5406_1.471. It has been rated as problematic. This issue affects some unknown processing of the component Access Point Setting Handler. The manipulation with the input 12345678 leads to use of hard-coded password. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version MW3_16U_5406_1.53 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-220769 was assigned to this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-0808

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Jan Mahn

Affected Vendor

Affected Software

Inverter
Vulnerable Versions:
MW3_15U_5406_1.47, MW3_15U_5406_1.471

Timeline

Official Publish: February 13th, 2023
Last Modified: August 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Weaknesses (CWE)