Junglewise Threat Intelligence

CVE-2025-64308: Brightpick Mission Control hardcoded credentials in JavaScript bundle

CVE-2025-64308 · Severity: medium · CVSS 6.5 · Published 2025-11-15

Technologies: Brightpick AI Mission Control, Brightpick Internal Logic Control. Vendors: Brightpick.

Executive brief

Brightpick Mission Control, a web application used to manage warehouse robotics and logistics, contains hardcoded credentials within its publicly accessible client-side code. An attacker with access to the local network could discover these credentials and use them to access the company's documentation portal. This could lead to the exposure of sensitive technical information or operational manuals intended only for authorized personnel.

Technical details

The vulnerability is classified as Unprotected Transport of Credentials (CWE-523) due to the inclusion of hardcoded credentials within the client-side JavaScript bundle of the Mission Control web application. An unauthenticated attacker on an adjacent network can extract these credentials by inspecting the application's static assets. These credentials provide unauthorized access to Brightpick AI's documentation portal. The issue affects all versions of Brightpick Mission Control / Internal Logic Control prior to version 1.67.0. The vendor has addressed this in version 1.67.0 by removing the hardcoded secrets from the client-side code.

Affected products

  • Brightpick AI Mission Control / Internal Logic Control < 1.67.0

Timeline

  • 2025-11-14: disclosed: Initial CVE publication
  • 2026-02-04: patched: Vendor released version 1.67.0 to mitigate the issue
  • 2026-06-23: advisory: CISA ICSA-25-317-04 advisory updated

References

Related threats