Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

CISA Alerts on Critical SunPower Vulnerability Allowing Full Device Takeover

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-severity alert (ICSA-25-245-03) regarding a critical vulnerability in SunPower’s PVS6 solar inverter series. This vulnerability allows attackers on adjacent networks to gain…

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-severity alert (ICSA-25-245-03) regarding a critical vulnerability in SunPower’s PVS6 solar inverter series. This vulnerability allows attackers on adjacent networks to gain control of the device.

Rated 9.4 out of 10 on the CVSS v4 scale, the vulnerability stems from hard-coded credentials in the Bluetooth Low Energy (BLE) servicing interface, posing a risk to energy infrastructure.

CISA warns that exploiting this vulnerability could enable adversaries to replace firmware, alter grid settings, disable power production, establish unauthorized SSH tunnels, and manipulate connected devices. Given the PVS6’s deployment in various solar installations, exploitation could disrupt power generation and damage equipment.

SunPower PVS6 units running firmware versions 2025.06 build 61839 and earlier are vulnerable. The vulnerability, tracked as CVE-2025-9696, arises from hard-coded encryption parameters in the BLE interface. An attacker within Bluetooth range can leverage these credentials to access the device’s servicing port.

The vulnerability is exploitable with low complexity and requires no user interaction or prior privileges, posing a significant threat to infrastructure. While the attack cannot be launched remotely, many installations expose Bluetooth interfaces without proper network segmentation.

This vulnerability allows attackers on adjacent networks to gain control of the device.
Lucas Norwood · Thehackingpost

Vulnerability: Use of hard-coded credentials in BLE servicing interface (CWE-798). CVSS v3.1 Base Score: 9.6 (AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). CVSS v4 Base Score: 9.4 (AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H). Researcher: Dagan Henderson. Affected Sectors: Energy, with global deployments. Release Date: Tue, Sep 2, 2025.

CISA’s advisory details that hard-coded credentials allow unauthorized commands to the servicing interface. Attackers can upload malicious firmware, introduce backdoors, and reconfigure settings to maintain access.

SunPower has not publicly responded to CISA’s coordination requests. CISA recommends the following measures:

Network Segmentation: Place PVS6 devices behind firewalls and separate from public networks. Disable or isolate Bluetooth interfaces. Limit Exposure: Remove direct internet access for control interfaces. Use VPNs with up-to-date firmware and multifactor authentication for remote servicing. Access Control: Implement strict Bluetooth pairing policies and monitor for unauthorized connections. Impact Analysis: Conduct risk assessments before deploying measures to ensure operational continuity.

Advertisement

CISA directs organizations to its ICS recommended practices portal for further guidance, including cybersecurity strategies and intrusion detection.

Users should avoid clicking unsolicited links and consult CISA’s phishing resources. While no active exploitation has been reported, the vulnerability remains dangerous until patched. Organizations should prioritize remediation.

Owners of SunPower PVS6 devices should verify firmware versions and seek updates from SunPower. Any malicious activity should be reported to CISA’s Incident Response Team.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories