Impact
Ghost Robotics’ Vision 60 mobile application APK version 5.5.0 contains an access control flaw that permits a malicious user to establish new, simultaneous sessions while a legitimate session is in progress, bypassing required client validation and session integrity checks. By exploiting this weakness, an attacker with a modified version of the app may intercept live data streams such as video, partially issue commands, and remain unseen as the original user continues to interact with the robot, thereby compromising the confidentiality of transmitted information and operational security.
Affected Systems
The only component currently known to be vulnerable is the Vision 60 robot’s mobile control app (APK 5.5.0). No other product lines or versions are listed as affected.
Risk and Exploitability
The CVSS score of 7.7 reflects high severity; the EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation, and the vulnerability is not present in the CISA KEV catalog. An attacker would need to supply a tampered version of the client and have network access to the robot—most likely over the local or remote control interface. The attack vector is inferred to be network‑based, requiring manipulation of the client application to bypass session validation.
OpenCVE Enrichment