Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3q83-gf9g-9qxm

Опубликовано: 27 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.7

Описание

An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session. This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational security.

An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session. This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational security.

EPSS

Процентиль: 3%
0.00131
Низкий

7.7 High

CVSS4

Дефекты

CWE-284

Связанные уязвимости

nvd
около 1 месяца назад

An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session. This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational security.

EPSS

Процентиль: 3%
0.00131
Низкий

7.7 High

CVSS4

Дефекты

CWE-284