CVE-2025-64309: CWE-523 in Brightpick AI Brightpick Mission Control / Internal Logic Control
The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The unauthenticated URL can be discovered through basic network scanning techniques.
AI Analysis
Technical Summary
The vulnerability identified as CVE-2025-64309 in Brightpick AI's Brightpick Mission Control / Internal Logic Control involves unauthorized disclosure of sensitive information through WebSocket traffic. When an unauthenticated user connects to a specific URL, device telemetry, configuration, and sensitive data are exposed. The URL can be found using basic network scanning techniques, making the vulnerability accessible remotely with low attack complexity and no required privileges or user interaction. The CVSS 3.1 base score is 7.4, reflecting high confidentiality impact and scope change, but no integrity or availability impact. All versions of the product are affected. No patch or remediation details are provided in the available data.
Potential Impact
The vulnerability leads to high confidentiality impact by exposing sensitive device telemetry and configuration data to unauthenticated remote attackers. This could allow attackers to gather intelligence about the device and its operation, potentially facilitating further attacks or unauthorized access. There is no direct impact on integrity or availability reported. The scope is changed, indicating that the vulnerability affects components beyond the initially vulnerable component.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch links are provided, users should monitor vendor communications for updates. Until a patch is available, restrict network access to the affected product to trusted users only and consider network-level controls to prevent unauthorized access to the specific WebSocket URL. Avoid exposing the product to untrusted networks.
CVE-2025-64309: CWE-523 in Brightpick AI Brightpick Mission Control / Internal Logic Control
Description
The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The unauthenticated URL can be discovered through basic network scanning techniques.
CVSS v3.1
Score 7.4high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2025-64309 in Brightpick AI's Brightpick Mission Control / Internal Logic Control involves unauthorized disclosure of sensitive information through WebSocket traffic. When an unauthenticated user connects to a specific URL, device telemetry, configuration, and sensitive data are exposed. The URL can be found using basic network scanning techniques, making the vulnerability accessible remotely with low attack complexity and no required privileges or user interaction. The CVSS 3.1 base score is 7.4, reflecting high confidentiality impact and scope change, but no integrity or availability impact. All versions of the product are affected. No patch or remediation details are provided in the available data.
Potential Impact
The vulnerability leads to high confidentiality impact by exposing sensitive device telemetry and configuration data to unauthenticated remote attackers. This could allow attackers to gather intelligence about the device and its operation, potentially facilitating further attacks or unauthorized access. There is no direct impact on integrity or availability reported. The scope is changed, indicating that the vulnerability affects components beyond the initially vulnerable component.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch links are provided, users should monitor vendor communications for updates. Until a patch is available, restrict network access to the affected product to trusted users only and consider network-level controls to prevent unauthorized access to the specific WebSocket URL. Avoid exposing the product to untrusted networks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- icscert
- Date Reserved
- 2025-10-29T17:40:55.209Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6917c086ed59478372495959
Added to database: 11/14/2025, 23:51:34 UTC
Last enriched: 06/26/2026, 12:29:33 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 198
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.