CISA Cảnh Báo Về Các Lỗ Hổng Nghiêm Trọng Trong Tigo Energy Cloud Connect Advanced

Tháng 8 05, 2025 • César Daniel Barreto

Tigo Energy Cloud Connect Advanced cybersecurity vulnerability alert CVSS 9.3

CISA issued advisory ICSA-25-217-02 on August 7, 2025, detailing three vulnerabilities in Tigo Energy’s Cloud Connect Advanced (CCA) — a gateway used to monitor and manage solar PV fleets. All versions up to and including 4.0.1 are affected, and together the flaws allow a full remote takeover of the device.

Hard-coded credentials, RCE, and forged sessions

The most serious is CVE-2025-7768, a use of hard-coded credentials rated CVSS v4.0 9.3 that hands an unauthorized user administrative access with no legitimate credentials at all. CVE-2025-7769 (CVSS v4.0 8.7) is a command-injection flaw in the /cgi-bin/mobile_api endpoint that enables remote arbitrary command execution. CVE-2025-7770 (CVSS v4.0 8.7) stems from predictable session-ID generation — session IDs are derived from the current timestamp, so an attacker can forge a valid session and bypass authentication.

A public exploit already exists

This is not a theoretical risk: a public proof-of-concept exploit for the command-injection flaw has been published, which lowers the bar for attackers considerably. CISA warns that successful exploitation could let an attacker change system settings, disrupt solar energy production, and interfere with safety mechanisms — moving the impact from data exposure into the physical, operational domain.

Mitigations

At the time of the advisory, Tigo Energy had not released a public patch and stated it was working on a fix; CISA directed users to Tigo’s Help Center for specific mitigations. Until a fix ships, defense rests on network controls: keep CCA devices off the internet, place them behind firewalls, isolate them from business and control networks, and use secure, up-to-date remote access. Given a public exploit and hard-coded credentials, any internet-exposed CCA should be treated as at immediate risk.

César Daniel Barreto, Tác giả về An ninh mạng tại Security Briefing

César Daniel Barreto

César Daniel Barreto là một nhà văn và chuyên gia an ninh mạng được kính trọng, nổi tiếng với kiến thức sâu rộng và khả năng đơn giản hóa các chủ đề an ninh mạng phức tạp. Với kinh nghiệm sâu rộng về bảo mật mạng và bảo vệ dữ liệu, ông thường xuyên đóng góp các bài viết và phân tích sâu sắc về các xu hướng an ninh mạng mới nhất, giáo dục cả chuyên gia và công chúng.

viVietnamese