PT-2025-43060 · Ghost Robotics · Vision 60
Published
2025-10-22
·
Updated
2025-10-22
·
CVE-2025-41109
CVSS v4.0
8.7
High
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Ghost Robotics Vision 60 version 0.27.2
Description
The Ghost Robotics Vision 60 robot, version 0.27.2, lacks authentication mechanisms when establishing connections through its physical interfaces, including three RJ45 connectors and a USB Type-C port. The robot’s internal router automatically assigns IP addresses to devices connected to it, allowing an attacker to connect a WiFi access point under their control and gain access to the robot’s network without credentials. Once inside the network, an attacker can monitor all data transmitted by the robot, as it operates on ROS 2 without default authentication.
Recommendations
Apply authentication mechanisms when establishing connections through the RJ45 connectors and USB Type-C port.
Implement network access controls to prevent unauthorized devices from connecting to the robot’s network.
Secure the ROS 2 environment with appropriate authentication protocols.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vision 60