Get real-time updates on Telegram
CVE-2025-64307: Brightpick Mission Control / Internal Logic Control 0 to before 1.67.0
CVE-2025-64307. CVSS 3.1 base score 6.5 (MEDIUM, Vendor/CNA). EPSS 0.00232 (percentile 0.1285), scored 2026-10-06.
Affected technology
Brightpick Mission Control / Internal Logic Control · 0 to before 1.67.0
Brightpick AI
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 4.0): Adjacent network · No privileges required · No user interaction required
What an attacker can do
An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes. Vendor/CNA’s CVSS 4.0 assessment (base score 7.1/10) rates confidentiality and availability impact as none; integrity impact as high.
- CWE
- CWE-306
- CCR priority
- 26.1 /100 (P4)
- CVSS 3.1
- 6.5 /10 · CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N · Vendor/CNA
- EPSS
- 0.00232 · percentile 0.1285 · 2026-10-06
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 23:02:50.240617+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-64307.html