Junglewise Threat Intelligence

CVE-2026-12991: Ghost Robotics Vision 60 lack of communication integrity and authenticity

CVE-2026-12991 · Severity: info · CVSS 8.7 · Published 2026-07-27

Executive brief

A security flaw in the Ghost Robotics Vision 60 quadruped robot allows an attacker on the same local network to hijack control of the device. By intercepting communications that lack proper encryption and authenticity checks, an unauthorized user can disconnect the legitimate operator and take over the robot's movements and functions. This could lead to a total loss of control over the hardware, potential physical damage, or unauthorized surveillance.

Technical details

The vulnerability is classified as a lack of cryptographic integrity and authenticity (CWE-300) in the communication channel between the operator's mobile application and the Vision 60 robot. An attacker positioned on the same local network (adjacent) can utilize ARP spoofing and selective traffic blocking to perform a man-in-the-middle attack. Because the communication protocol does not verify the authenticity of packets, the attacker can inject commands, manipulate data, and prevent the legitimate controller from regaining access. This results in a complete compromise of confidentiality, integrity, and availability for the robot's operations. As of the advisory date, no patch or solution has been reported.

Affected products

  • Ghost Robotics Vision 60 APK v5.5.0

Timeline

  • 2026-07-27: advisory: Initial disclosure by INCIBE-CERT
  • 2026-07-27: disclosed: Vulnerability published to NVD

References