Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allowing remote code execution due to improper handling of user input. When used with default credentials, this enables attackers to execute arbitrary commands on the device that could cause potential unauthorized access, service disruption, and data exposure.
History

Tue, 12 Aug 2025 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Tigo Energy
Tigo Energy cloud Connect Advanced
Vendors & Products Tigo Energy
Tigo Energy cloud Connect Advanced

Wed, 06 Aug 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 06 Aug 2025 21:00:00 +0000

Type Values Removed Values Added
Description Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allowing remote code execution due to improper handling of user input. When used with default credentials, this enables attackers to execute arbitrary commands on the device that could cause potential unauthorized access, service disruption, and data exposure.
Title Improper Neutralization of Special Elements used in a Command ('Command Injection') in Tigo Energy Cloud Connect Advanced
Weaknesses CWE-77
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2025-08-06T20:42:47.338Z

Updated: 2025-08-06T20:51:40.366Z

Reserved: 2025-07-17T15:44:00.440Z

Link: CVE-2025-7769

cve-icon Vulnrichment

Updated: 2025-08-06T20:51:35.985Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-06T21:15:32.627

Modified: 2025-08-07T21:26:37.453

Link: CVE-2025-7769

cve-icon Redhat

No data.