---
id: CVE-2025-64307
title: >-
  The Brightpick Internal Logic Control web interface is accessible without
  requiring user authentication
summary: >-
  The Brightpick Internal Logic Control web interface is accessible without
  requiring user authentication. An unauthorized user could exploit this
  interface to manipulate robot control functions, including initiating or
  halting runners, as…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-306
published: '2025-11-15'
updated: '2026-06-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64307'
references:
  - url: 'https://brightpick.ai/contact-us/'
    label: ics-cert@hq.dhs.gov
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-317-04.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-25-317-04'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00232
epssPercentile: 0.14325
ingestedAt: '2026-06-26T16:43:13.612Z'
---

## Overview

The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
