CVE 9.4 CRITICAL

Use of Hard-coded Credentials in SunPower PVS6_CVE-2025-9696

9.4 / 10
CRITICAL
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

The SunPower PVS6's BluetoothLE interface is vulnerable due to its use of hardcoded encryption parameters and publicly accessible protocol details. An attacker within Bluetooth range could exploit this vulnerability to gain full access to the device's servicing interface. This access allows the attacker to perform actions such as firmware replacement, disabling power production, modifying grid settings, creating SSH tunnels, altering firewall settings, and manipulating connected devices.

Basic Information

ID CVE-2025-9696
Source icscert
Published Sep 2, 2025 at 16:34
Modified Sep 2, 2025 at 17:39

Affected Product

Vendor SunPower
Product PVS6
Affected Versions SunPower PVS6 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.