HomeSecurityCISA: Warns of critical vulnerability in SunPower devices

CISA: Warns of critical vulnerability in SunPower devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical vulnerability in SunPower PVS6 solar power devices. The vulnerability could allow attackers to gain complete control of the systems.

SunPower CISA vulnerability

SunPower: Vulnerability CVE-2025-9696

The vulnerability, tracked as CVE-2025-9696, results from the use of hardcoded credentials in BluetoothLE , presenting a significant threat to solar energy infrastructure worldwide. It affects SunPower PVS6 versions 2025.06 build 61839 and earlier and has received a CVSS v4 score of 9.4/10.

See also: Hackers leverage Hexstrike-AI for Zero Day exploit

Attackers within Bluetooth range can exploit this vulnerability to gain access to the device's service interface. This allows them to replace firmware, disable power generation, modify network settings, create SSH tunnels, change firewall settings, and manipulate connected devices.

According to CISA analysts, the vulnerability exploits hardcoded encryption parameters and publicly accessible protocol details within the BluetoothLE implementation. This design flaw turns what should be a secure maintenance interface into an open gateway for malicious actors. Only adjacent network access, which means this vulnerability is particularly worrisome for solar power installations in densely populated areas.

CISA: Warns of critical vulnerability in SunPower devices

Attack mechanism and exploitation

The vulnerability exploits an inherent weakness in the PVS6 authentication system, where static credentials provide an easy entry point for attackers. Once an attacker establishes a Bluetooth connection using these hardcoded parameters, they gain administrative privileges equivalent to those of legitimate service personnel.

See also: PoC Exploit for RCE vulnerability in IIS Web Deploy

The exploitation process involves reverse-engineering publicly available protocol documentation to identify the authentication sequence.

# Simplified representation of the vulnerability bluetooth_connection = establish_ble_connection(target_device) if authenticate_with_hardcoded_key(DEFAULT_SERVICE_KEY): admin_access = True execute_firmware_replacement() modify_power_settings()

The effectiveness of the attack lies in its simplicity – no complex exploits or zero-day techniques are required. Attackers could potentially develop automated tools to scan vulnerable devices and systematically compromise them.

The impact of the vulnerability extends beyond individual devices, as compromised units could act as access points to broader energy infrastructure networks. Notably, SunPower has not responded to CISA’s coordination efforts, leaving users without official updates.

The vulnerability in the SunPower PVS6 devices highlights a fundamental issue in the energy technology space: the transition to “ smart” infrastructure often precedes the mature integration of strong security measures. The fact that critical devices still rely on hardcoded credentials shows that energy industries treat cybersecurity more as an afterthought than an integral part of the design.

See also: CISA: New TP-Link and WhatsApp vulnerabilities in the KEV Catalog

This has serious consequences. Solar energy, promoted worldwide as a key pillar of the green transition, is becoming a target with a double value: on the one hand, a breach of such systems could destabilize energy production, and on the other, create entry points into wider infrastructure networks. The simplicity of the exploitation, as described, means that even non-specialized actors could exploit the weakness, especially in areas where installations are dense and easily accessible.

CISA: Warns of critical vulnerability in SunPower devices

Equally concerning is the delay or lack of immediate response from SunPower. In an industry where trust and reliability are crucial, the inability to provide immediate patches or interim measures creates a dangerous vacuum.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Protection

CISA recommends implementing network isolation, using VPNs for remote access , and deploying comprehensive monitoring systems to detect unauthorized access attempts. Organizations should prioritize updating affected devices as patches become available and consider temporarily disabling Bluetooth functionality where operationally feasible.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS