{"id":"CVE-2025-64307","title":"The Brightpick Internal Logic Control web interface is accessible without requiring user authentication","summary":"The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, as…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-306"],"published":"2025-11-15","updated":"2026-06-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-64307","references":[{"url":"https://brightpick.ai/contact-us/","label":"ics-cert@hq.dhs.gov"},{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-317-04.json","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-25-317-04","label":"ics-cert@hq.dhs.gov"}],"tags":["nvd"],"epss":0.00232,"epssPercentile":0.14304,"ingestedAt":"2026-06-26T16:43:13.612Z","slug":"CVE-2025-64307","body":"## Overview\n\nThe Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}