Outback Power Mojave Inverter Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the Outback Power Mojave Inverter, which is used in residential grid-connected battery backup systems. This vulnerability allows attackers to inject commands through specially crafted post requests. Additionally, the inverter's use of the GET request method for sensitive information exposes it to unauthorized data access. All versions of the Outback Power Mojave Inverter are affected.

Impact

Exploitation of this vulnerability could lead to unauthorized command execution on the affected inverter.

Remediation

Users are advised to disable the networking features of the Mojave Inverter until a replacement product can be acquired. CISA recommends taking defensive measures to minimize the risk of exploitation, such as disabling unused functions, minimizing network exposure for control system devices, and using secure remote access methods like virtual private networks (VPNs).

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.7
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.