PT-2025-47031 · Brightpick · Brightpick Mission Control

Published

2025-11-14

·

Updated

2025-11-20

·

CVE-2025-64309

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Brightpick Mission Control (affected versions not specified)
Description Brightpick Mission Control discloses device telemetry, configuration, and credential information via WebSocket traffic to unauthenticated users connecting to a specific URL. The URL can be discovered through basic network scanning techniques.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-64309

Affected Products

Brightpick Mission Control