CVE-2025-64309

The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The unauthenticated URL can be discovered through basic network scanning techniques.
Configurations

No configuration.

History

25 Jun 2026, 23:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.6
v2 : unknown
v3 : 7.4
Summary (en) Brightpick Mission Control discloses device telemetry, configuration, and credential information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The unauthenticated URL can be discovered through basic network scanning techniques. (en) The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The unauthenticated URL can be discovered through basic network scanning techniques.

15 Nov 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-15 00:15

Updated : 2026-06-25 23:17


NVD link : CVE-2025-64309

Mitre link : CVE-2025-64309

CVE.ORG link : CVE-2025-64309


JSON object : View

Products Affected

No product.

CWE
CWE-523

Unprotected Transport of Credentials