PT-2025-43061 · Ghost Robotics · Vision 60

Published

2025-10-22

·

Updated

2025-10-30

·

CVE-2025-41110

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghost Robotics Vision 60 version 0.27.2
Description The Ghost Robotics Vision 60 APK version 0.27.2 contains exposed encrypted WiFi and SSH credentials. An attacker can connect to the robot’s WiFi network and access all its data, as the system operates on ROS 2 without default authentication. Furthermore, an attacker can connect via SSH and gain complete control of the robot, potentially causing physical damage to the robot or its surroundings.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-41110

Affected Products

Vision 60