CVE-2025-9696: Use of Hard-coded Credentials in SunPower PVS6
The SunPower PVS6's BluetoothLE interface is vulnerable due to its use of hardcoded encryption parameters and publicly accessible protocol details. An attacker within Bluetooth range could exploit this vulnerability to gain full access to the device's servicing interface. This access allows the attacker to perform actions such as firmware replacement, disabling power production, modifying grid settings, creating SSH tunnels, altering firewall settings, and manipulating connected devices.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9696?
CVE-2025-9696 is classified as a high severity vulnerability due to its potential to allow unauthorized access to the device's servicing interface.
How do I fix CVE-2025-9696?
To mitigate CVE-2025-9696, update the SunPower PVS6 to a version after 2025.06 build 61839 that addresses this vulnerability.
Who is affected by CVE-2025-9696?
CVE-2025-9696 affects SunPower PVS6 devices, specifically versions 2025.06 build 61839 and prior.
What type of access can be gained through CVE-2025-9696?
An attacker exploiting CVE-2025-9696 can gain full access to the servicing interface of the device.
What is the attack vector for CVE-2025-9696?
The attack vector for CVE-2025-9696 requires the attacker to be within Bluetooth range of the vulnerable SunPower PVS6 device.