CVE-2025-7768

CRITICAL

Tigo Energy CCA - Privilege Escalation

Title source: llm
STIX 2.1

Description

Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credentials that allow unauthorized users to gain administrative access. This vulnerability enables attackers to escalate privileges and take full control of the device, potentially modifying system settings, disrupting solar energy production, and interfering with safety mechanisms.

Scores

CVSS v4 9.3
EPSS 0.0008
EPSS Percentile 23.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-798
Status published
Products (1)
Tigo Energy/Cloud Connect Advanced < 4.0.1
Published Aug 06, 2025
Tracked Since Feb 18, 2026