The Brightpick Internal Logic Control web interface is accessible
without requiring user authentication. An unauthorized user could
exploit this interface to manipulate robot control functions, including
initiating or halting runners, assigning jobs, clearing stations, and
deploying storage totes.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Brightpick AI has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of the affected products are encouraged to contact Brightpick AI https://brightpick.ai/contact-us/ for additional information.

History

Tue, 18 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 15 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Brightpick Ai
Brightpick Ai internal Logic Control
Vendors & Products Brightpick Ai
Brightpick Ai internal Logic Control

Fri, 14 Nov 2025 23:45:00 +0000

Type Values Removed Values Added
Description The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes.
Title Brightpick Mission Control / Internal Logic Control Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-11-17T16:51:31.868Z

Reserved: 2025-10-29T17:40:55.207Z

Link: CVE-2025-64307

cve-icon Vulnrichment

Updated: 2025-11-17T16:51:27.964Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-15T00:15:47.700

Modified: 2025-11-18T14:06:55.963

Link: CVE-2025-64307

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-15T22:07:39Z

Weaknesses