PT-2026-64897 · Ghost Robotics · Vision 60
CVE-2026-12991
·
Published
2026-07-27
·
Updated
2026-07-27
CVSS v4.0
8.7
High
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Ghost Robotics Vision 60 version 5.5.0
Description
The system lacks cryptographic mechanisms to ensure the integrity and authenticity of communications, making it susceptible to man-in-the-middle attacks. An attacker on the local network can employ ARP spoofing (a technique used to link a MAC address to a legitimate IP address on a local network) and selective traffic blocking to intercept and manipulate packets between the operator and the robot. This enables the attacker to disconnect the original controller and establish unauthorized communications, preventing the operator from regaining control of the device.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vision 60