Description
A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization mechanisms, the attacker can view real-time camera feeds, control the robot’s movements, manage sensors (GPS, RTK, SAM, LIDAR), and execute critical operational commands (Play, Pause, Stop, E-Stop). Successful exploitation completely compromises the confidentiality, integrity, and physical security of the system.
Published: 2026-07-27
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A lack of authentication in Ghost Robotics Vision 60’s mobile app (APK v5.5.0) permits an unauthenticated attacker who is connected to the device’s internal Wi‑Fi network to freely access the web administration interface and the HTTP API. This grants the attacker the ability to view real‑time camera feeds, command the robot’s movements, manage sensors such as GPS, RTK, SAM, and LIDAR, and execute critical operational commands (Play, Pause, Stop, E‑Stop). The vulnerability effectively gives an attacker full control over the robot, compromising confidentiality, integrity, and physical security of the system.

Affected Systems

The affected product is Ghost Robotics’ Vision 60 robot, specifically the mobile app version 5.5.0 and its embedded web administration interface. The weakness is present in the app and the robot’s internal network services and will affect any deployment that uses the listed app version.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability, and the EPSS score is less than 1 %, suggesting a low probability of exploitation. The issue is not listed in CISA’s KEV catalog. The likely attack vector is local network‑based; an attacker must be able to connect to the device’s internal Wi‑Fi, either physically or by compromising a local segment. Once inside, the lack of authentication allows unrestricted command execution, posing a significant risk to operational safety.

Generated by OpenCVE AI on August 3, 2026 at 17:48 UTC.

Remediation

Vendor Solution

No solution has been reported at this time.


OpenCVE Recommended Actions

  • Because no official patch is available yet, isolate the Vision 60 robot on a separate, secured Wi‑Fi network or block the internal network so that only trusted personnel can access it.
  • Disable or firewall the web administration interface and HTTP API endpoints to prevent unauthenticated access, and enforce strict network segmentation so that only authorized devices can communicate with the robot.
  • Continuously monitor for suspicious activity and keep the system documentation up to date while awaiting vendor updates or a formal patch from Ghost Robotics.
  • Be aware that no vendor update has been released and that temporary mitigations must remain in place until an official fix is issued.

Generated by OpenCVE AI on August 3, 2026 at 17:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Ghost Robotics
Ghost Robotics vision 60
Vendors & Products Ghost Robotics
Ghost Robotics vision 60

Mon, 27 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization mechanisms, the attacker can view real-time camera feeds, control the robot’s movements, manage sensors (GPS, RTK, SAM, LIDAR), and execute critical operational commands (Play, Pause, Stop, E-Stop). Successful exploitation completely compromises the confidentiality, integrity, and physical security of the system.
Title Multiple vulnerabilities in Ghost Robotics' Vision 60
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Ghost Robotics Vision 60
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-07-27T15:46:22.000Z

Reserved: 2026-06-23T12:14:08.725Z

Link: CVE-2026-12989

cve-icon Vulnrichment

Updated: 2026-07-27T15:46:18.229Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T13:16:51.993

Modified: 2026-07-27T20:32:11.620

Link: CVE-2026-12989

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:00:11Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function