cbcvebase.

Ghost Robotics Vision 60 vulnerabilities

3 known vulnerabilities affecting ghost_robotics/vision_60.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2025-41108P2CRITICALCVSS 9.8v0.27.22025-10-22
CVE-2025-41108 [CRITICAL] CWE-287 CVE-2025-41108: The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker t The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker to send commands to the robot from an external attack station, impersonating the control station (tablet) and gaining unauthorised full control of the robot. The absence of encryption and authentication mechanisms in the communication protocol allows
nvd
CVE-2025-41110P3HIGHCVSS 8.8v0.27.22025-10-22
CVE-2025-41110 [HIGH] CWE-287 CVE-2025-41110: Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This vuln Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This vulnerability allows an attacker to connect to the robot's WiFi and view all its data, as it runs on ROS 2 without default authentication. In addition, the attacker can connect via SSH and gain full control of the robot, which could cause physical damage to
nvd
CVE-2025-41109P4MEDIUMCVSS 4.6v0.27.22025-10-22
CVE-2025-41109 [MEDIUM] CWE-798 CVE-2025-41109: Ghost Robotics Vision 60 v0.27.2 includes, among its physical interfaces, three RJ45 connectors and Ghost Robotics Vision 60 v0.27.2 includes, among its physical interfaces, three RJ45 connectors and a USB Type-C port. The vulnerability is due to the lack of authentication mechanisms when establishing connections through these ports. Specifically, with regard to network connectivity, the robot's internal router automatically assigns IP addresses to
nvd
Ghost Robotics Vision 60 vulnerabilities | cvebase