CVE-2025-64307

The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes.
Configurations

No configuration.

History

No history.

Information

Published : 2025-11-15 00:15

Updated : 2025-11-18 14:06


NVD link : CVE-2025-64307

Mitre link : CVE-2025-64307

CVE.ORG link : CVE-2025-64307


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function