Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allowing remote code execution due to improper handling of user input. When used with default credentials, this enables attackers to execute arbitrary commands on the device that could cause potential unauthorized access, service disruption, and data exposure.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Aug 2025 08:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Tigo Energy
Tigo Energy cloud Connect Advanced |
|
Vendors & Products |
Tigo Energy
Tigo Energy cloud Connect Advanced |
Wed, 06 Aug 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 06 Aug 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allowing remote code execution due to improper handling of user input. When used with default credentials, this enables attackers to execute arbitrary commands on the device that could cause potential unauthorized access, service disruption, and data exposure. | |
Title | Improper Neutralization of Special Elements used in a Command ('Command Injection') in Tigo Energy Cloud Connect Advanced | |
Weaknesses | CWE-77 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: icscert
Published: 2025-08-06T20:42:47.338Z
Updated: 2025-08-06T20:51:40.366Z
Reserved: 2025-07-17T15:44:00.440Z
Link: CVE-2025-7769

Updated: 2025-08-06T20:51:35.985Z

Status : Awaiting Analysis
Published: 2025-08-06T21:15:32.627
Modified: 2025-08-07T21:26:37.453
Link: CVE-2025-7769

No data.