PT-2025-35584 · Sunpower · Sunpower Pvs6
Dagan Henderson
·
Published
2025-09-02
·
Updated
2025-09-03
·
CVE-2025-9696
CVSS v4.0
9.4
Critical
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
SunPower PVS6 (affected versions not specified)
Description
The SunPower PVS6’s BluetoothLE interface is vulnerable due to the use of hardcoded encryption parameters and publicly accessible protocol details. An attacker within Bluetooth range could gain full access to the device’s servicing interface. This access allows actions such as firmware replacement, disabling power production, modifying grid settings, creating SSH tunnels, altering firewall settings, and manipulating connected devices. A real-world incident has been reported where a user discovered the vulnerability and was able to identify the potential to shutdown power production.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sunpower Pvs6