Authentication Flaw in Ghost Robotics Vision 60 Mobile App Exposes Device Controls
CVE-2026-12989
8.7HIGH
What is CVE-2026-12989?
The Ghost Robotics Vision 60 mobile app (APK v5.5.0) contains a significant authentication flaw, enabling an unauthenticated attacker connected to the device's internal Wi-Fi network to access the web administration interface and the HTTP API without authorization. This exploit grants complete control over vital functionalities including real-time camera feeds, robotic movement, and sensor management (GPS, RTK, SAM, LIDAR). The absence of robust authorization mechanisms poses severe security risks, allowing attackers to execute critical operational commands, thereby undermining the system's confidentiality, integrity, and physical security.
Affected Version(s)
Vision 60 5.5.0
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
VĂctor Manuel Charro GarcĂa, AdriĂĄn Campazas Vega and Claudia Ălvarez Aparicio.
