The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes.
History

Sat, 15 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Brightpick Ai
Brightpick Ai internal Logic Control
Vendors & Products Brightpick Ai
Brightpick Ai internal Logic Control

Fri, 14 Nov 2025 23:45:00 +0000

Type Values Removed Values Added
Description The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes.
Title Brightpick Mission Control / Internal Logic Control Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-11-14T23:34:59.659Z

Reserved: 2025-10-29T17:40:55.207Z

Link: CVE-2025-64307

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-15T00:15:47.700

Modified: 2025-11-15T00:15:47.700

Link: CVE-2025-64307

cve-icon Redhat

No data.