Man-in-the-Middle Vulnerability in Ghost Robotics Vision 60 Robot
CVE-2026-12991

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-12991?

The Ghost Robotics Vision 60 robot, specifically in APK version 5.5.0, suffers from a lack of cryptographic mechanisms to ensure the integrity and authenticity of its communications. This vulnerability allows an attacker situated on the local network to exploit ARP spoofing and selective traffic blocking techniques. By intercepting and manipulating packets exchanged between the operator and the robot, the attacker can disrupt the original controller's connection, establish unauthorized communications, and effectively prevent the operator from re-establishing control. This breach significantly compromises the system's confidentiality, integrity, and availability of operational capabilities.

Affected Version(s)

Vision 60 5.5.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Víctor Manuel Charro García, Adriån Campazas Vega and Claudia Álvarez Aparicio
.