CVE-2026-12989
Received Received - Intake

Authentication Bypass in Ghost Robotics Vision 60 Mobile App

Vulnerability report for CVE-2026-12989, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)

Description

A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization mechanisms, the attacker can view real-time camera feeds, control the robot’s movements, manage sensors (GPS, RTK, SAM, LIDAR), and execute critical operational commands (Play, Pause, Stop, E-Stop). Successful exploitation completely compromises the confidentiality, integrity, and physical security of the system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ghost_robotics vision_60 5.5.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a lack of authentication in Ghost Robotics' Vision 60 robot's mobile app (APK v5.5.0). An attacker on the device's internal Wi-Fi network can access the web administration interface and HTTP API without authentication. This allows full control over the robot, including camera feeds, movement, sensors, and critical commands.

Detection Guidance

Scan your network for devices running the Ghost Robotics Vision 60 mobile app (APK v5.5.0) on its internal Wi-Fi network. Check for open ports and HTTP services on the robot's interface. Use tools like nmap to identify exposed web administration interfaces or APIs.

Impact Analysis

An attacker could view sensitive real-time data, manipulate the robot's operations, or disable safety features. This compromises confidentiality, integrity, and physical security of the system and its environment.

Compliance Impact

This vulnerability likely violates data protection and privacy regulations such as GDPR and HIPAA due to unauthorized access to sensitive data and lack of proper access controls. It could result in non-compliance penalties and legal consequences.

Mitigation Strategies

Disable the internal Wi-Fi network of the robot if not required. Implement network segmentation to isolate the robot from other systems. Update the mobile app to a version that includes authentication mechanisms. Restrict access to the web administration interface via firewall rules.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12989. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart