VYPR

CCA

by Tigo Energy

CVEs (2)

  • CVE-2025-7769HigAug 6, 2025
    risk 0.60cvss epss 0.07

    Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allowing remote code execution due to improper handling of user input. When used with default credentials, this enables attackers to…

  • CVE-2025-7770HigAug 6, 2025
    risk 0.57cvss epss 0.00

    Tigo Energy's CCA device is vulnerable to insecure session ID generation in their remote API. The session IDs are generated using a predictable method based on the current timestamp, allowing attackers to recreate valid session IDs. When combined with the ability to circumvent…