CVE 6.5 MEDIUM

Brightpick Mission Control / Internal Logic Control Missing Authentication for Critical Function_CVE-2025-64307

6.5 / 10
MEDIUM
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Description

The Brightpick Internal Logic Control web interface is accessible
without requiring user authentication. An unauthorized user could
exploit this interface to manipulate robot control functions, including
initiating or halting runners, assigning jobs, clearing stations, and
deploying storage totes.

Basic Information

ID CVE-2025-64307
Source icscert
Published Nov 14, 2025 at 23:34

Affected Product

Vendor Brightpick AI
Product Brightpick Mission Control / Internal Logic Control
Version All versions
Affected Versions Brightpick AI Brightpick Mission Control / Internal Logic Control All versions

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.