Back to overview

CVE-2026-12991

HIGH
8.7
CVSS 4.0
Description
The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and manipulate packets between the legitimate operator and the robot. This allows the attacker to disconnect the original controller, establish unauthorized communications, and prevent the operator from regaining control of the device, seriously compromising the confidentiality, integrity, and availability (CIA) of operations.

Metadata

CVE ID
CVE-2026-12991
State
PUBLISHED
Assigner
INCIBE
Reserved
2026-06-23 12:14 UTC
Published
2026-07-27 11:44 UTC
Last updated
2026-07-27 15:45 UTC
Primary CWE
CWE-300
CWE-300 Channel Accessible by Non-Endpoint
Vendor / Product
Ghost Robotics / Vision 60
Sources
cve.org  ·  NVD

Severity & Metrics

8.7 HIGH CVSS 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Ghost Robotics Vision 60 5.5.0
Weakness (CWE)
CWESourceDescription
CWE-300 cna CWE-300 Channel Accessible by Non-Endpoint
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.7 HIGH 4.0 cna CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Back to overview