Impact
A lack of authentication in Ghost Robotics Vision 60’s mobile app (APK v5.5.0) permits an unauthenticated attacker who is connected to the device’s internal Wi‑Fi network to freely access the web administration interface and the HTTP API. This grants the attacker the ability to view real‑time camera feeds, command the robot’s movements, manage sensors such as GPS, RTK, SAM, and LIDAR, and execute critical operational commands (Play, Pause, Stop, E‑Stop). The vulnerability effectively gives an attacker full control over the robot, compromising confidentiality, integrity, and physical security of the system.
Affected Systems
The affected product is Ghost Robotics’ Vision 60 robot, specifically the mobile app version 5.5.0 and its embedded web administration interface. The weakness is present in the app and the robot’s internal network services and will affect any deployment that uses the listed app version.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability, and the EPSS score is less than 1 %, suggesting a low probability of exploitation. The issue is not listed in CISA’s KEV catalog. The likely attack vector is local network‑based; an attacker must be able to connect to the device’s internal Wi‑Fi, either physically or by compromising a local segment. Once inside, the lack of authentication allows unrestricted command execution, posing a significant risk to operational safety.
OpenCVE Enrichment