CVE-2025-64309
Brightpick Mission Control
discloses device telemetry, configuration, and credential information
via WebSocket traffic
Brightpick Mission Control discloses device telemetry, configuration, and credential information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The unauthenticated URL can be discovered through basic network scanning techniques.
HIGH · CVSS 8.6
EPSS 0.00101
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0