CVE-2025-41109

MEDIUM
Published Oct 22, 2025 Modified Oct 31, 2025 CWE-798

Description

Ghost Robotics Vision 60 v0.27.2 includes, among its physical interfaces, three RJ45 connectors and a USB Type-C port. The vulnerability is due to the lack of authentication mechanisms when establishing connections through these ports. Specifically, with regard to network connectivity, the robot's internal router automatically assigns IP addresses to any device physically connected to it. An attacker could connect a WiFi access point under their control to gain access to the robot's network without needing the credentials for the deployed network. Once inside, the attacker can monitor all its data, as the robot runs on ROS 2 without authentication by default.

Is your site exposed to CVE-2025-41109?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

4.6
MEDIUM
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weakness Type (CWE)

CWE-798 CWE-798

Affected Products

Vendor Product
ghostrobotics vision_60_firmware
ghostrobotics vision_60

References

Frequently Asked Questions

What is CVE-2025-41109? +
Ghost Robotics Vision 60 v0.27.2 includes, among its physical interfaces, three RJ45 connectors and a USB Type-C port. The vulnerability is due to the lack of authentication mechanisms when establishing connections through these ports. Specifically, with regard to network connectivity, the robot's internal router automatically assigns IP addresses to any device physically connected to it. An attacker could connect a WiFi access point under their control to gain access to the robot's network without needing the credentials for the deployed network. Once inside, the attacker can monitor all its data, as the robot runs on ROS 2 without authentication by default. It has a CVSS v3.1 base score of 4.6 (MEDIUM).
How severe is CVE-2025-41109? +
CVE-2025-41109 has a CVSS v3.1 score of 4.6 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2025-41109? +
CVE-2025-41109 affects products from ghostrobotics, specifically: vision_60, vision_60_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2025-41109? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-41109 — free, no signup required.