CVE-2025-64307

MEDIUM

Brightpick Internal Logic Control - Unauthenticated RCE

Title source: llm
STIX 2.1

Description

The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes.

Scores

CVSS v3 6.5
EPSS 0.0004
EPSS Percentile 13.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
Brightpick AI/Brightpick Mission Control / Internal Logic Control All versions
Published Nov 15, 2025
Tracked Since Feb 18, 2026