Command Injection Vulnerability in Ghost Robotics Vision 60 by Ghost Robotics
CVE-2025-41108
9.2CRITICAL
What is CVE-2025-41108?
The Ghost Robotics Vision 60 version 0.27.2 is vulnerable due to its insecure communication protocol that allows attackers to manipulate commands sent to the robot. By exploiting this weakness, an attacker can impersonate the control tablet and gain unauthorized access, leading to full control over the robotic system. The lack of encryption and authentication facilitates the interception of legitimate traffic, which an attacker can replicate to issue any valid command. This vulnerability is heightened by the use of the widely understood MAVLink protocol, making it critical for users to enhance their security measures, especially when using Wi-Fi and 4G/LTE connectivity.
Affected Version(s)
Vision 60 0.27.2
References
CVSS V4
Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
AdriĂĄn Campazas Vega
Claudia Ălvarez Aparicio
Pedro Cabrera CĂĄmara
Miguel Gallego Vara
Javier Valero MartĂ
