Command Injection Vulnerability in Tigo Energy CCA System
CVE-2025-7769
8.7HIGH
What is CVE-2025-7769?
The Tigo Energy CCA system is susceptible to a command injection vulnerability at the /cgi-bin/mobile_api endpoint. This flaw occurs when the DEVICE_PING command is invoked, allowing improper handling of user input. An attacker exploiting this vulnerability, particularly with default credentials, can execute arbitrary commands on the device. This may lead to unauthorized access, potential service disruptions, and exposure of sensitive data, posing significant risks to the integrity and availability of the system.
Affected Version(s)
Cloud Connect Advanced 0 <= 4.0.1
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Anthony Rose of BC Security
Jacob Krasnov of BC Security
Peter Kariuki of Ovanova