CISA figyelmeztet a kritikus Tigo Energy Cloud Connect Advanced hibákra
augusztus 05, 2025 • César Daniel Barreto

CISA issued advisory ICSA-25-217-02 on August 7, 2025, detailing three vulnerabilities in Tigo Energy’s Cloud Connect Advanced (CCA) — a gateway used to monitor and manage solar PV fleets. All versions up to and including 4.0.1 are affected, and together the flaws allow a full remote takeover of the device.
Hard-coded credentials, RCE, and forged sessions
The most serious is CVE-2025-7768, a use of hard-coded credentials rated CVSS v4.0 9.3 that hands an unauthorized user administrative access with no legitimate credentials at all. CVE-2025-7769 (CVSS v4.0 8.7) is a command-injection flaw in the /cgi-bin/mobile_api endpoint that enables remote arbitrary command execution. CVE-2025-7770 (CVSS v4.0 8.7) stems from predictable session-ID generation — session IDs are derived from the current timestamp, so an attacker can forge a valid session and bypass authentication.
A public exploit already exists
This is not a theoretical risk: a public proof-of-concept exploit for the command-injection flaw has been published, which lowers the bar for attackers considerably. CISA warns that successful exploitation could let an attacker change system settings, disrupt solar energy production, and interfere with safety mechanisms — moving the impact from data exposure into the physical, operational domain.
Mitigations
At the time of the advisory, Tigo Energy had not released a public patch and stated it was working on a fix; CISA directed users to Tigo’s Help Center for specific mitigations. Until a fix ships, defense rests on network controls: keep CCA devices off the internet, place them behind firewalls, isolate them from business and control networks, and use secure, up-to-date remote access. Given a public exploit and hard-coded credentials, any internet-exposed CCA should be treated as at immediate risk.

César Dániel Barreto
César Daniel Barreto elismert kiberbiztonsági író és szakértő, aki mélyreható ismereteiről és képességéről ismert, hogy egyszerűsítse a bonyolult kiberbiztonsági témákat. Kiterjedt tapasztalattal rendelkezik a hálózatbiztonság és az adatvédelem terén, rendszeresen hozzájárul betekintő cikkekkel és elemzésekkel a legújabb kiberbiztonsági trendekről, oktatva mind a szakembereket, mind a nagyközönséget.