Vulnerability Database

310,450

Total vulnerabilities in the database

CVE-2025-64307

The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes.

  • Published: Nov 15, 2025
  • Updated: Nov 16, 2025
  • CVE: CVE-2025-64307
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6.5
  • AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CWEs: