KACO Inverters exposed via hardcoded credential flaw
Multiple KACO blueplanet inverters contain a weak credential generation algorithm allowing attackers to derive technical service credentials from device serial numbers.
CISA has published an advisory detailing two vulnerabilities in Siemens KACO blueplanet inverters widely deployed in energy infrastructure. CVE-2025-40946 describes a CRC16-based algorithm used to generate technical service credentials that can be derived from the device's serial number, enabling unauthorized access. CVE-2026-41125 is a SQL injection vulnerability in the KACO Meteor server that allows authenticated attackers to escalate privileges over local networks.
The vulnerabilities affect over 30 inverter models across the blueplanet product line. KACO has released firmware version 6.1.4.9 for several GEN2 models and version 3.91 for gridsafe variants, but many affected products have no fix available or planned. The vendor recommends operators implement network segmentation, firewall protections, and VPN access controls as compensating measures.
Given the critical infrastructure context and the ease of exploiting predictable credentials, this advisory warrants immediate attention from energy sector organizations using KACO equipment. Operators should validate their grid protection schemes include appropriate redundancy and isolation to mitigate potential impacts from compromised inverters.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-160-02
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free