CVE-2025-64307 MEDIUM

CVE-2025-64307: Brightpick Mission Control / Internal Logic Control Missing Authentication for Critical Function

Vendor Brightpick Ai
Product Brightpick Mission Control / Internal Logic Control
Weakness CWE-306 · Missing auth
Published November 14, 2025
Last update November 17, 2025

CVSS base score

6.5/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes.

Key dates

02Disclosure timeline

November 14, 2025 CVE published
November 17, 2025 Record updated