Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hhwr-hq3f-7f8r

Опубликовано: 15 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes.

The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes.

EPSS

Процентиль: 13%
0.00042
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 6.5
nvd
3 месяца назад

The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes.

EPSS

Процентиль: 13%
0.00042
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-306