Description
Brightpick Mission Control discloses device telemetry, configuration, and credential information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The unauthenticated URL can be discovered through basic network scanning techniques.
Problem types
Product status
All versions
Credits
Souvik Kandar reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-317-04
github.com/...p/csaf_files/OT/white/2025/icsa-25-317-04.json