What is CVE-2026-12991?
The absence of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks via ARP spoofing. This affects devices on local networks, where an attacker can intercept and manipulate traffic. It is recommended to isolate affected robots and implement network segmentation until a security update is available.
Azərbaycanca: Ghost Robotics Vision 60 robotunun APK v5.5.0 versiyasında kommunikasiya trafikinin bütövlüyü və autentifikasiyası üçün kriptoqrafik mexanizmlərin olmaması aşkar edilib. Bu zəiflik lokal şəbəkədə olan təcavüzkara ARP spoofing istifadə edərək trafikə müdaxilə etməyə imkan verir. Cihazın işlədildiyi lokal şəbəkələrdə təhlükəsizlik tədbirlərini gücləndirmək tövsiyə olunur.
FAQ2
Which version of the Ghost Robotics Vision 60 robot is affected by CVE-2026-12991?
This vulnerability was discovered in APK version 5.5.0 of the robot.
What attack method can an attacker use to exploit CVE-2026-12991?
An attacker on the local network can intercept traffic using ARP spoofing.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.