CVE-2026-12989 PUBLISHED

Multiple vulnerabilities in Ghost Robotics' Vision 60

Assigner: INCIBE
Reserved: 23.06.2026 Published: 27.07.2026 Updated: 27.07.2026

A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization mechanisms, the attacker can view real-time camera feeds, control the robot’s movements, manage sensors (GPS, RTK, SAM, LIDAR), and execute critical operational commands (Play, Pause, Stop, E-Stop). Successful exploitation completely compromises the confidentiality, integrity, and physical security of the system.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Ghost Robotics
Product Vision 60
Versions Default: unaffected
  • Version 5.5.0 is affected

Solutions

No solution has been reported at this time.

Credits

  • Víctor Manuel Charro García, Adrián Campazas Vega and Claudia Álvarez Aparicio. finder

References

Problem Types

  • CWE-306 Missing authentication for critical function CWE