CVE-2026-12989

Ghost Robotics · Vision 60

The Ghost Robotics Vision 60 mobile application (APK version 5.5.0) suffers from a lack of authentication for critical functions, allowing unauthorized access via the local network.

Executive summary

A critical authentication bypass in the Ghost Robotics Vision 60 mobile application allows unauthenticated attackers on the local network to gain total control over the robot.

Vulnerability

This is a missing authentication for critical function vulnerability (CWE-306). It allows an attacker with network access (AV:A) to interact with the robot's control systems without providing any credentials.

Business impact

With a CVSS score of 8.7, this vulnerability poses a severe risk, as it allows for unauthorized physical control of the robotic system. Successful exploitation could lead to total loss of operational control, physical safety risks, or the compromise of sensitive data collected by the unit.

Remediation

Immediate Action: No official patch is currently available. Organizations should restrict network access to the mobile application and the connected hardware to only authorized, air-gapped, or strictly controlled management networks.

Proactive Monitoring: Monitor network traffic to the Vision 60 control interface for any unauthorized connection attempts or anomalous commands.

Compensating Controls: Place the robot control interface behind a hardware firewall or an isolated VLAN that requires VPN authentication for any inbound access.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the lack of a vendor-provided patch, users must treat this vulnerability as critical and immediately isolate the affected systems from any untrusted or public-facing networks. Ensure that rigorous network-level access controls are in place until an official firmware or application update is released.