Tigo Energy's CCA device is vulnerable to insecure session ID generation in their remote API. The session IDs are generated using a predictable method based on the current timestamp, allowing attackers to recreate valid session IDs. When combined with the ability to circumvent session ID requirements for certain commands, this enables unauthorized access to sensitive device functions on connected solar optimization systems.
History

Tue, 12 Aug 2025 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Tigo Energy
Tigo Energy cloud Connect Advanced
Vendors & Products Tigo Energy
Tigo Energy cloud Connect Advanced

Thu, 07 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 06 Aug 2025 21:00:00 +0000

Type Values Removed Values Added
Description Tigo Energy's CCA device is vulnerable to insecure session ID generation in their remote API. The session IDs are generated using a predictable method based on the current timestamp, allowing attackers to recreate valid session IDs. When combined with the ability to circumvent session ID requirements for certain commands, this enables unauthorized access to sensitive device functions on connected solar optimization systems.
Title Predictable Seed in Pseudo-Random Number Generator (PRNG) in Tigo Energy Cloud Connect Advanced
Weaknesses CWE-337
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2025-08-06T20:45:06.780Z

Updated: 2025-08-07T14:49:00.875Z

Reserved: 2025-07-17T15:44:01.345Z

Link: CVE-2025-7770

cve-icon Vulnrichment

Updated: 2025-08-07T14:48:56.197Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-06T21:15:32.793

Modified: 2025-08-07T21:26:37.453

Link: CVE-2025-7770

cve-icon Redhat

No data.