PT-2025-43061 · Ghost Robotics · Vision 60

CVE-2025-41110

·

Published

2025-10-22

·

Updated

2025-10-30

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghost Robotics Vision 60 version 0.27.2
Description The Ghost Robotics Vision 60 APK version 0.27.2 contains exposed encrypted WiFi and SSH credentials. An attacker can connect to the robot’s WiFi network and access all its data, as the system operates on ROS 2 without default authentication. Furthermore, an attacker can connect via SSH and gain complete control of the robot, potentially causing physical damage to the robot or its surroundings.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-41110

Affected Products

Vision 60