Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credentials that allow unauthorized users to gain administrative access. This vulnerability enables attackers to escalate privileges and take full control of the device, potentially modifying system settings, disrupting solar energy production, and interfering with safety mechanisms.
History

Tue, 12 Aug 2025 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Tigo Energy
Tigo Energy cloud Connect Advanced
Vendors & Products Tigo Energy
Tigo Energy cloud Connect Advanced

Wed, 06 Aug 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 06 Aug 2025 20:45:00 +0000

Type Values Removed Values Added
Description Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credentials that allow unauthorized users to gain administrative access. This vulnerability enables attackers to escalate privileges and take full control of the device, potentially modifying system settings, disrupting solar energy production, and interfering with safety mechanisms.
Title Use of Hard-coded Credentials in Tigo Energy Cloud Connect Advanced
Weaknesses CWE-798
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2025-08-06T20:28:43.631Z

Updated: 2025-08-06T20:41:11.923Z

Reserved: 2025-07-17T15:43:59.428Z

Link: CVE-2025-7768

cve-icon Vulnrichment

Updated: 2025-08-06T20:41:08.733Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-06T21:15:32.460

Modified: 2025-08-07T21:26:37.453

Link: CVE-2025-7768

cve-icon Redhat

No data.