The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes.
History

Tue, 18 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 15 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Brightpick Ai
Brightpick Ai internal Logic Control
Vendors & Products Brightpick Ai
Brightpick Ai internal Logic Control

Fri, 14 Nov 2025 23:45:00 +0000

Type Values Removed Values Added
Description The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes.
Title Brightpick Mission Control / Internal Logic Control Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2025-11-14T23:34:59.659Z

Updated: 2025-11-17T16:51:31.868Z

Reserved: 2025-10-29T17:40:55.207Z

Link: CVE-2025-64307

cve-icon Vulnrichment

Updated: 2025-11-17T16:51:27.964Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-15T00:15:47.700

Modified: 2025-11-18T14:06:55.963

Link: CVE-2025-64307

cve-icon Redhat

No data.