Description
The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and manipulate packets between the legitimate operator and the robot. This allows the attacker to disconnect the original controller, establish unauthorized communications, and prevent the operator from regaining control of the device, seriously compromising the confidentiality, integrity, and availability (CIA) of operations.
Published: 2026-07-27
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Ghost Robotics Vision 60 robot (APK v5.5.0) lacks cryptographic integrity and authenticity checks for its communications, allowing an attacker who can access the local network to intercept and modify packets between the operator and the robot. The attacker can disconnect the legitimate controller, establish unauthorized links, and prevent the operator from regaining control, thereby compromising confidentiality, integrity, and availability of the robot’s operation.

Affected Systems

The vulnerability affects Ghost Robotics Vision 60 robot units running APK version 5.5.0.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, and with an attacker present on the local network the risk is substantial; the EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local‑network man‑in‑the‑middle using ARP spoofing or selective traffic blocking. Exploitation requires the attacker to be on the same wireless or wired segment as the robot and the operator, after which they can intercept, modify, or block traffic, leading to loss of control over the robot.

Generated by OpenCVE AI on August 3, 2026 at 17:47 UTC.

Remediation

Vendor Solution

No solution has been reported at this time.


OpenCVE Recommended Actions

  • Isolate the robot within its own VLAN or physical network segment and restrict inbound traffic to the known operator IP addresses via firewall rules.
  • Deploy ARP spoofing detection or enable static ARP assignment for the robot to block unauthorized ARP responses.
  • Until a firmware update provides encrypting communications, route all operator traffic through a secure VPN tunnel to add authentication and integrity to the control channel.
  • No official patch has been released; continue monitoring vendor announcements for an update.

Generated by OpenCVE AI on August 3, 2026 at 17:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Ghost Robotics
Ghost Robotics vision 60
Vendors & Products Ghost Robotics
Ghost Robotics vision 60

Mon, 27 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and manipulate packets between the legitimate operator and the robot. This allows the attacker to disconnect the original controller, establish unauthorized communications, and prevent the operator from regaining control of the device, seriously compromising the confidentiality, integrity, and availability (CIA) of operations.
Title Multiple vulnerabilities in Ghost Robotics' Vision 60
Weaknesses CWE-300
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Ghost Robotics Vision 60
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-07-27T15:45:09.693Z

Reserved: 2026-06-23T12:14:10.688Z

Link: CVE-2026-12991

cve-icon Vulnrichment

Updated: 2026-07-27T15:45:04.568Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T13:16:52.250

Modified: 2026-07-27T20:32:11.620

Link: CVE-2026-12991

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:00:11Z

Weaknesses
  • CWE-300

    Channel Accessible by Non-Endpoint