A vulnerability in Ghost Robotics' Vision 60 robot (APK v5.5.0) allows man-in-the-middle attacks due to lack of cryptographic mechanisms. An attacker on the local network can intercept and manipulate packets between the operator and the robot, compromising CIA of operations. This issue is particularly concerning for organizations using this robot in critical infrastructure, defense, or security-sensitive sectors.
CVE-2026-12989 is a high-severity vulnerability affecting the Ghost Robotics Vision 60 robot's mobile app (APK v5.5.0). The vulnerability is caused by a lack of authentication, allowing unauthenticated attackers to gain unrestricted access to the web administration interface and HTTP API. This allows attackers to view real-time camera feeds, control the robot's movements, manage sensors (GPS, RTK, SAM, LI [truncated]