CVE-2025-64307

Severity CVSS v4.0:
HIGH
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
15/11/2025
Last modified:
15/11/2025

Description

The Brightpick Internal Logic Control web interface is accessible <br /> without requiring user authentication. An unauthorized user could <br /> exploit this interface to manipulate robot control functions, including <br /> initiating or halting runners, assigning jobs, clearing stations, and <br /> deploying storage totes.