Junglewise Threat Intelligence

CVE-2025-64307: Brightpick Mission Control missing authentication in Internal Logic Control

CVE-2025-64307 · Severity: medium · CVSS 6.5 · Published 2025-11-15

Technologies: Brightpick AI Mission Control, Brightpick Internal Logic Control. Vendors: Brightpick.

Executive brief

Brightpick warehouse robots are managed by a control interface that was found to be accessible without any password or authentication. An unauthorized person on the local network could use this interface to take control of the robots, including starting or stopping them and changing their assigned tasks. This could lead to significant operational disruptions, safety risks, or physical damage within a warehouse or fulfillment center.

Technical details

A missing authentication vulnerability (CWE-306) exists in the Brightpick Internal Logic Control web interface. The flaw allows an unauthenticated attacker with adjacent network access to interact directly with the robot control system. Exploitation enables the manipulation of critical functions, such as initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes. The vendor has addressed this by implementing a reverse-proxy authentication layer between the public load balancer and the internal service in version 1.67.0.

Affected products

  • Brightpick AI Mission Control / Internal Logic Control < 1.67.0

Timeline

  • 2025-11-14: disclosed
  • 2025-11-15: advisory
  • 2026-02-04: patched: Vendor released version 1.67.0

References

Related threats