Authentication Flaw in Ghost Robotics Vision 60 Mobile App Exposes Device Controls
CVE-2026-12989

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-12989?

The Ghost Robotics Vision 60 mobile app (APK v5.5.0) contains a significant authentication flaw, enabling an unauthenticated attacker connected to the device's internal Wi-Fi network to access the web administration interface and the HTTP API without authorization. This exploit grants complete control over vital functionalities including real-time camera feeds, robotic movement, and sensor management (GPS, RTK, SAM, LIDAR). The absence of robust authorization mechanisms poses severe security risks, allowing attackers to execute critical operational commands, thereby undermining the system's confidentiality, integrity, and physical security.

Affected Version(s)

Vision 60 5.5.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Víctor Manuel Charro García, Adriån Campazas Vega and Claudia Álvarez Aparicio.
.