Impact
Ghost Robotics Vision 60 robot (APK v5.5.0) lacks cryptographic integrity and authenticity checks for its communications, allowing an attacker who can access the local network to intercept and modify packets between the operator and the robot. The attacker can disconnect the legitimate controller, establish unauthorized links, and prevent the operator from regaining control, thereby compromising confidentiality, integrity, and availability of the robot’s operation.
Affected Systems
The vulnerability affects Ghost Robotics Vision 60 robot units running APK version 5.5.0.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and with an attacker present on the local network the risk is substantial; the EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local‑network man‑in‑the‑middle using ARP spoofing or selective traffic blocking. Exploitation requires the attacker to be on the same wireless or wired segment as the robot and the operator, after which they can intercept, modify, or block traffic, leading to loss of control over the robot.
OpenCVE Enrichment