VYPR

CCA

by Tigo Energy

CVEs (3)

  • CVE-2025-7769HigAug 6, 2025
    risk 0.61cvss epss 0.16

    Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allowing remote code execution due to improper handling of user input. When used with default credentials, this enables attackers to…

  • CVE-2025-7768CriAug 6, 2025
    risk 0.60cvss epss 0.01

    Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credentials that allow unauthorized users to gain administrative access. This vulnerability enables attackers to escalate privileges and take full control of the device, potentially modifying system settings,…

  • CVE-2025-7770HigAug 6, 2025
    risk 0.57cvss epss 0.01

    Tigo Energy's CCA device is vulnerable to insecure session ID generation in their remote API. The session IDs are generated using a predictable method based on the current timestamp, allowing attackers to recreate valid session IDs. When combined with the ability to circumvent…