ID

VAR-202508-0152


CVE

CVE-2025-7769


TITLE

Tigo Energy Cloud Connect Advanced Command Injection Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2025-23131

DESCRIPTION

Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allowing remote code execution due to improper handling of user input. When used with default credentials, this enables attackers to execute arbitrary commands on the device that could cause potential unauthorized access, service disruption, and data exposure. Tigo Energy Cloud Connect Advanced is a compact data logger from the US company Tigo Energy. This vulnerability could allow an attacker to execute arbitrary commands on the system

Trust: 1.44

sources: NVD: CVE-2025-7769 // CNVD: CNVD-2025-23131

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-23131

AFFECTED PRODUCTS

vendor:tigomodel:energy cloud connect advancedscope:lteversion:<=4.0.1

Trust: 0.6

sources: CNVD: CNVD-2025-23131

CVSS

SEVERITY

CVSSV2

CVSSV3

ics-cert@hq.dhs.gov: CVE-2025-7769
value: HIGH

Trust: 1.0

CNVD: CNVD-2025-23131
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-23131
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2025-23131 // NVD: CVE-2025-7769

PROBLEMTYPE DATA

problemtype:CWE-77

Trust: 1.0

sources: NVD: CVE-2025-7769

PATCH

title:Patch for Tigo Energy Cloud Connect Advanced Command Injection Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/740566

Trust: 0.6

sources: CNVD: CNVD-2025-23131

EXTERNAL IDS

db:NVDid:CVE-2025-7769

Trust: 1.6

db:ICS CERTid:ICSA-25-217-02

Trust: 1.6

db:CNVDid:CNVD-2025-23131

Trust: 0.6

sources: CNVD: CNVD-2025-23131 // NVD: CVE-2025-7769

REFERENCES

url:https://www.cisa.gov/news-events/ics-advisories/icsa-25-217-02

Trust: 1.6

sources: CNVD: CNVD-2025-23131 // NVD: CVE-2025-7769

SOURCES

db:CNVDid:CNVD-2025-23131
db:NVDid:CVE-2025-7769

LAST UPDATE DATE

2025-10-10T23:31:05.211000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-23131date:2025-10-09T00:00:00
db:NVDid:CVE-2025-7769date:2025-08-07T21:26:37.453

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-23131date:2025-10-09T00:00:00
db:NVDid:CVE-2025-7769date:2025-08-06T21:15:32.627