Back

HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') in Tigo Energy Cloud Connect Advanced

Published Aug 6, 2025

Description

Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allowing remote code execution due to improper handling of user input. When used with default credentials, this enables attackers to execute arbitrary commands on the device that could cause potential unauthorized access, service disruption, and data exposure.

Affected products

Remediation

Vendor solution

Tigo Energy is aware of these vulnerabilities and is actively working on a fix to address them.

Visit Tigo Energy's Help Center for more specific security recommendations.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner icscert
Published Aug 6, 2025
Updated Aug 6, 2025
Reserved Jul 17, 2025

CISA Vulnrichment

Updated Aug 6, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner icscert
Published Aug 6, 2025
Updated Aug 6, 2025

GitHub

No data