PT-2025-35584 · Sunpower · Sunpower Pvs6

Dagan Henderson

·

Published

2025-09-02

·

Updated

2025-09-03

·

CVE-2025-9696

CVSS v4.0

9.4

Critical

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions SunPower PVS6 (affected versions not specified)
Description The SunPower PVS6’s BluetoothLE interface is vulnerable due to the use of hardcoded encryption parameters and publicly accessible protocol details. An attacker within Bluetooth range could gain full access to the device’s servicing interface. This access allows actions such as firmware replacement, disabling power production, modifying grid settings, creating SSH tunnels, altering firewall settings, and manipulating connected devices. A real-world incident has been reported where a user discovered the vulnerability and was able to identify the potential to shutdown power production.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-9696

Affected Products

Sunpower Pvs6