Bluetooth Vulnerability in SunPower PVS6 Renewable Energy Systems
CVE-2025-9696

9.4CRITICAL

Key Information:

Vendor

Sunpower

Status
Vendor
CVE Published:
2 September 2025

What is CVE-2025-9696?

The BluetoothLE interface of the SunPower PVS6 is compromised due to hardcoded encryption parameters and publicly accessible protocols. This gap allows an attacker within Bluetooth range to exploit the vulnerability, gaining unauthorized access to the device's servicing interface. Once accessed, an attacker can execute critical actions, including firmware alteration, power production disruptions, grid setting modifications, SSH tunnel creation, firewall adjustments, and manipulation of connected devices, posing significant risks to operational security and integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

PVS6 0 <= 2025.06 build 61839

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dagan Henderson
.