Executive brief
A security flaw in the mobile application for the Ghost Robotics Vision 60 quadruped robot allows unauthorized users to hijack control of the device. By using a modified version of the app, an attacker can connect to the robot while a legitimate operator is already using it. This allows the attacker to secretly view real-time video feeds and interfere with the robot's operations without alerting the primary user.
Technical details
The vulnerability is classified as Improper Access Control (CWE-284) within the Vision 60 mobile application (APK v5.5.0). The system fails to perform adequate client validation or session integrity checks, which allows the robot to maintain multiple concurrent sessions. An attacker on the same adjacent network (e.g., the robot's internal Wi-Fi) can use a modified version of the mobile application to join an existing session. This enables the attacker to bypass control restrictions, intercept real-time telemetry and video, and issue commands without terminating the legitimate operator's connection. No patch has been reported at this time.
Affected products
- Ghost Robotics Vision 60 Mobile App (APK) 5.5.0
Timeline
- 2026-07-27: advisory: Initial disclosure by INCIBE-CERT