CVE-2025-64307

The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes.
Configurations

No configuration.

History

15 Nov 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-15 00:15

Updated : 2025-11-18 14:06


NVD link : CVE-2025-64307

Mitre link : CVE-2025-64307

CVE.ORG link : CVE-2025-64307


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function