CISA figyelmeztet a kritikus Tigo Energy Cloud Connect Advanced hibákra

augusztus 05, 2025 • César Daniel Barreto

Tigo Energy Cloud Connect Advanced cybersecurity vulnerability alert CVSS 9.3

CISA issued advisory ICSA-25-217-02 on August 7, 2025, detailing three vulnerabilities in Tigo Energy’s Cloud Connect Advanced (CCA) — a gateway used to monitor and manage solar PV fleets. All versions up to and including 4.0.1 are affected, and together the flaws allow a full remote takeover of the device.

Hard-coded credentials, RCE, and forged sessions

The most serious is CVE-2025-7768, a use of hard-coded credentials rated CVSS v4.0 9.3 that hands an unauthorized user administrative access with no legitimate credentials at all. CVE-2025-7769 (CVSS v4.0 8.7) is a command-injection flaw in the /cgi-bin/mobile_api endpoint that enables remote arbitrary command execution. CVE-2025-7770 (CVSS v4.0 8.7) stems from predictable session-ID generation — session IDs are derived from the current timestamp, so an attacker can forge a valid session and bypass authentication.

A public exploit already exists

This is not a theoretical risk: a public proof-of-concept exploit for the command-injection flaw has been published, which lowers the bar for attackers considerably. CISA warns that successful exploitation could let an attacker change system settings, disrupt solar energy production, and interfere with safety mechanisms — moving the impact from data exposure into the physical, operational domain.

Mitigations

At the time of the advisory, Tigo Energy had not released a public patch and stated it was working on a fix; CISA directed users to Tigo’s Help Center for specific mitigations. Until a fix ships, defense rests on network controls: keep CCA devices off the internet, place them behind firewalls, isolate them from business and control networks, and use secure, up-to-date remote access. Given a public exploit and hard-coded credentials, any internet-exposed CCA should be treated as at immediate risk.

César Daniel Barreto, kiberbiztonsági szerző a Security Briefingnél

César Dániel Barreto

César Daniel Barreto elismert kiberbiztonsági író és szakértő, aki mélyreható ismereteiről és képességéről ismert, hogy egyszerűsítse a bonyolult kiberbiztonsági témákat. Kiterjedt tapasztalattal rendelkezik a hálózatbiztonság és az adatvédelem terén, rendszeresen hozzájárul betekintő cikkekkel és elemzésekkel a legújabb kiberbiztonsági trendekről, oktatva mind a szakembereket, mind a nagyközönséget.

Login

Already have an account? Sign in to pick up where you left off.

Register

New here? Create an account to follow our latest security briefings.

hu_HUHungarian