CISA Alerts on Critical SunPower Vulnerability Allowing Full Device Takeover
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-severity alert (ICSA-25-245-03) regarding a critical vulnerability in SunPower’s PVS6 solar inverter series. This vulnerability allows attackers on adjacent networks to gain…
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-severity alert (ICSA-25-245-03) regarding a critical vulnerability in SunPower’s PVS6 solar inverter series. This vulnerability allows attackers on adjacent networks to gain control of the device.
Rated 9.4 out of 10 on the CVSS v4 scale, the vulnerability stems from hard-coded credentials in the Bluetooth Low Energy (BLE) servicing interface, posing a risk to energy infrastructure.
CISA warns that exploiting this vulnerability could enable adversaries to replace firmware, alter grid settings, disable power production, establish unauthorized SSH tunnels, and manipulate connected devices. Given the PVS6’s deployment in various solar installations, exploitation could disrupt power generation and damage equipment.
SunPower PVS6 units running firmware versions 2025.06 build 61839 and earlier are vulnerable. The vulnerability, tracked as CVE-2025-9696, arises from hard-coded encryption parameters in the BLE interface. An attacker within Bluetooth range can leverage these credentials to access the device’s servicing port.
The vulnerability is exploitable with low complexity and requires no user interaction or prior privileges, posing a significant threat to infrastructure. While the attack cannot be launched remotely, many installations expose Bluetooth interfaces without proper network segmentation.
This vulnerability allows attackers on adjacent networks to gain control of the device.
Vulnerability: Use of hard-coded credentials in BLE servicing interface (CWE-798). CVSS v3.1 Base Score: 9.6 (AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). CVSS v4 Base Score: 9.4 (AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H). Researcher: Dagan Henderson. Affected Sectors: Energy, with global deployments. Release Date: Tue, Sep 2, 2025.
CISA’s advisory details that hard-coded credentials allow unauthorized commands to the servicing interface. Attackers can upload malicious firmware, introduce backdoors, and reconfigure settings to maintain access.
SunPower has not publicly responded to CISA’s coordination requests. CISA recommends the following measures:
Network Segmentation: Place PVS6 devices behind firewalls and separate from public networks. Disable or isolate Bluetooth interfaces. Limit Exposure: Remove direct internet access for control interfaces. Use VPNs with up-to-date firmware and multifactor authentication for remote servicing. Access Control: Implement strict Bluetooth pairing policies and monitor for unauthorized connections. Impact Analysis: Conduct risk assessments before deploying measures to ensure operational continuity.
CISA directs organizations to its ICS recommended practices portal for further guidance, including cybersecurity strategies and intrusion detection.
Users should avoid clicking unsolicited links and consult CISA’s phishing resources. While no active exploitation has been reported, the vulnerability remains dangerous until patched. Organizations should prioritize remediation.
Owners of SunPower PVS6 devices should verify firmware versions and seek updates from SunPower. Any malicious activity should be reported to CISA’s Incident Response Team.
Based on reporting by GBHackers.
