Multiple vulnerabilities in Ghost Robotics' Vision 60

Posted date 27/07/2026
Identificador
INCIBE-2026-508
Importance
4 - High
Affected Resources

Vision 60, 5.5.0 APK version.

Description

INCIBE has coordinated the disclosure of three high-severity vulnerabilities affecting Ghost Robotics' Vision 60, an advanced quadruped robot. The vulnerabilities were discovered by Víctor Manuel Charro García, Adrián Campazas Vega and Claudia Álvarez Aparicio.

These vulnerabilities have been assigned the following codes, CVSS v4.0 base score, CVSS vector, and CWE vulnerability type for each vulnerability:

  • CVE-2026-12989: CVSS v4.0: 8.7 | CVSS AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N | CWE-306
  • CVE-2026-12990: CVSS v4.0: 7.7 | CVSS AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N | CWE-284
  • CVE-2026-12991: CVSS v4.0: 8.7 | CVSS AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N | CWE-300
Solution

No solution has been reported at this time.

Detail
  • CVE-2026-12989: a lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization mechanisms, the attacker can view real-time camera feeds, control the robot’s movements, manage sensors (GPS, RTK, SAM, LIDAR), and execute critical operational commands (Play, Pause, Stop, E-Stop). Successful exploitation completely compromises the confidentiality, integrity, and physical security of the system.
  • CVE-2026-12990: an access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session. This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational security.
  • CVE-2026-12991: the lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and manipulate packets between the legitimate operator and the robot. This allows the attacker to disconnect the original controller, establish unauthorized communications, and prevent the operator from regaining control of the device, seriously compromising the confidentiality, integrity, and availability (CIA) of operations.
CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2026-12989 Alta No Ghost Robotics
CVE-2026-12990 Alta No Ghost Robotics
CVE-2026-12991 Alta No Ghost Robotics
References list