VYPR

Vision 60

by Ghost Robotics

CVEs (6)

  • CVE-2025-41108CriOct 22, 2025
    risk 0.64cvss 9.8epss 0.00

    The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker to send commands to the robot from an external attack station, impersonating the control station (tablet) and gaining unauthorised full control of the robot. The absence of…

  • CVE-2025-41110HigOct 22, 2025
    risk 0.57cvss 8.8epss 0.00

    Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This vulnerability allows an attacker to connect to the robot's WiFi and view all its data, as it runs on ROS 2 without default authentication. In addition, the attacker can connect via…

  • CVE-2025-41109MedOct 22, 2025
    risk 0.30cvss 4.6epss 0.01

    Ghost Robotics Vision 60 v0.27.2 includes, among its physical interfaces, three RJ45 connectors and a USB Type-C port. The vulnerability is due to the lack of authentication mechanisms when establishing connections through these ports. Specifically, with regard to network…

  • CVE-2026-12991HigJul 27, 2026
    risk 0.00cvss epss 0.00

    The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic…

  • CVE-2026-12990HigJul 27, 2026
    risk 0.00cvss epss 0.00

    An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot…

  • CVE-2026-12989HigJul 27, 2026
    risk 0.00cvss epss 0.00

    A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of…