FLIR records
17 published records for vendor flir.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 5.9%
- Pre-auth RCE
- 4
- With a fix record
- 35.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-306 Missing Authentication for Critical Function2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-266 Incorrect Privilege Assignment1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
69This week | CVE-2022-37061Weaponized | All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection.flir · flir ax8 firmware · CWE-78 | Critical9.8 | — | 99.6% | Aug 18, 2022 |
48Plan | CVE-2023-51126Proof of concept | Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value paramflir · flir ax8 firmware · CWE-77 | Critical9.8 | — | 31.1% | Jan 10, 2024 |
40Plan | CVE-2023-29861No exploit | An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the managemenflir · dvtel camera firmware · CWE-94 | Critical9.8 | — | 1.8% | May 15, 2023 |
39Monitor | CVE-2018-3813No exploit | getConfigExportFile.cgi on FLIR Brickstream 2300 devices 2.0 4.1.53.166 has Incorrect Access Control, as demonstrated by reading the AVI_USEflir · brickstream 2300 2d firmware · CWE-200 | Critical9.8 | — | 1.2% | Jan 1, 2018 |
37Monitor | CVE-2018-25138No exploit | FLIR AX8 Thermal Camera 1.32.16 Hard-Coded Credentials Authentication Bypassflir · flir ax8 firmware · CWE-798 | Critical9.3 | — | 0.6% | Dec 24, 2025 |
36Monitor | CVE-2022-37060No exploit | FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access restrictiflir · flir ax8 firmware · CWE-22 | High7.5 | — | 18.4% | Aug 18, 2022 |
34Monitor | CVE-2018-25139No exploit | FLIR AX8 Thermal Camera 1.32.16 Unauthenticated RTSP Stream Disclosureflir · flir ax8 firmware · CWE-306 | High8.7 | — | 0.5% | Dec 24, 2025 |
31Monitor | CVE-2022-37062No exploit | All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability due to an improper flir · flir ax8 firmware · CWE-306 | High7.5 | — | 3.2% | Aug 18, 2022 |
31Monitor | CVE-2018-12920No exploit | Brickstream 2300 devices allow remote attackers to obtain potentially sensitive information via a direct request for the basic.html#ipsettinflir · brickstream 2300 firmware · CWE-200 | High7.5 | — | 1.8% | Jun 28, 2018 |
30Monitor | CVE-2025-5126No exploit | Teledyne FLIR AX8 settingsregional.php setDataTime command injectionflir · flir ax8 firmware · CWE-74 | High7.4 | — | 4.8% | May 24, 2025 |
30Monitor | CVE-2023-51127Proof of concept | FLIR AX8 thermal sensor cameras up to and including 1.46.16 are vulnerable to Directory Traversal due to improper access restriction.flir · flir ax8 firmware · CWE-22 | High7.5 | — | 1.3% | Jan 10, 2024 |
23Monitor | CVE-2022-4364No exploit | Teledyne FLIR AX8 Web Service palette.php command injectionflir · flir ax8 firmware · CWE-74 | Medium5.5 | — | 4.3% | Dec 8, 2022 |
21Monitor | CVE-2022-37063No exploit | All FLIR AX8 thermal sensor cameras versions up to and including 1.46.16 are vulnerable to Cross Site Scripting (XSS) due to improper input flir · flir ax8 firmware · CWE-79 | Medium5.4 | — | 1.6% | Aug 18, 2022 |
15Monitor | CVE-2024-3013No exploit | Teledyne FLIR AX8 User Registration test_login.php improper authorizationflir · flir ax8 firmware · CWE-266 | Low2.1 | — | 23.0% | Mar 27, 2024 |
10Monitor | CVE-2025-5695No exploit | Teledyne FLIR AX8 Backend subscriptions.php subscribe_to_alarm command injectionflir · flir ax8 firmware · CWE-74 | Low2.0 | — | 7.3% | Jun 5, 2025 |
8Monitor | CVE-2025-5127No exploit | Teledyne FLIR AX8 prod.php cross site scriptingflir · flir ax8 firmware · CWE-79 | Low2.0 | — | 0.8% | May 24, 2025 |
8Monitor | CVE-2025-6266No exploit | Teledyne FLIR AX8 upload.php unrestricted uploadflir · flir ax8 firmware · CWE-284 | Low2.1 | — | 0.5% | Jun 19, 2025 |
- CVE-2022-3706169This week
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection.
CriticalCVSS 9.8WeaponizedEPSS 100%flir · flir ax8 firmwareAug 18, 2022
- CVE-2023-5112648Plan
Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value param
CriticalCVSS 9.8Proof of conceptEPSS 31%flir · flir ax8 firmwareJan 10, 2024
- CVE-2023-2986140Plan
An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the managemen
CriticalCVSS 9.8No exploitEPSS 2%flir · dvtel camera firmwareMay 15, 2023
- CVE-2018-381339Monitor
getConfigExportFile.cgi on FLIR Brickstream 2300 devices 2.0 4.1.53.166 has Incorrect Access Control, as demonstrated by reading the AVI_USE
CriticalCVSS 9.8No exploitEPSS 1%flir · brickstream 2300 2d firmwareJan 1, 2018
- CVE-2018-2513837Monitor
FLIR AX8 Thermal Camera 1.32.16 Hard-Coded Credentials Authentication Bypass
CriticalCVSS 9.3No exploitEPSS 1%flir · flir ax8 firmwareDec 24, 2025
- CVE-2022-3706036Monitor
FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access restricti
HighCVSS 7.5No exploitEPSS 18%flir · flir ax8 firmwareAug 18, 2022
- CVE-2018-2513934Monitor
FLIR AX8 Thermal Camera 1.32.16 Unauthenticated RTSP Stream Disclosure
HighCVSS 8.7No exploitEPSS 1%flir · flir ax8 firmwareDec 24, 2025
- CVE-2022-3706231Monitor
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability due to an improper
HighCVSS 7.5No exploitEPSS 3%flir · flir ax8 firmwareAug 18, 2022
- CVE-2018-1292031Monitor
Brickstream 2300 devices allow remote attackers to obtain potentially sensitive information via a direct request for the basic.html#ipsettin
HighCVSS 7.5No exploitEPSS 2%flir · brickstream 2300 firmwareJun 28, 2018
- CVE-2025-512630Monitor
Teledyne FLIR AX8 settingsregional.php setDataTime command injection
HighCVSS 7.4No exploitEPSS 5%flir · flir ax8 firmwareMay 24, 2025
- CVE-2023-5112730Monitor
FLIR AX8 thermal sensor cameras up to and including 1.46.16 are vulnerable to Directory Traversal due to improper access restriction.
HighCVSS 7.5Proof of conceptEPSS 1%flir · flir ax8 firmwareJan 10, 2024
- CVE-2022-436423Monitor
Teledyne FLIR AX8 Web Service palette.php command injection
MediumCVSS 5.5No exploitEPSS 4%flir · flir ax8 firmwareDec 8, 2022
- CVE-2022-3706321Monitor
All FLIR AX8 thermal sensor cameras versions up to and including 1.46.16 are vulnerable to Cross Site Scripting (XSS) due to improper input
MediumCVSS 5.4No exploitEPSS 2%flir · flir ax8 firmwareAug 18, 2022
- CVE-2024-301315Monitor
Teledyne FLIR AX8 User Registration test_login.php improper authorization
LowCVSS 2.1No exploitEPSS 23%flir · flir ax8 firmwareMar 27, 2024
- CVE-2025-569510Monitor
Teledyne FLIR AX8 Backend subscriptions.php subscribe_to_alarm command injection
LowCVSS 2.0No exploitEPSS 7%flir · flir ax8 firmwareJun 5, 2025
- CVE-2025-51278Monitor
Teledyne FLIR AX8 prod.php cross site scripting
LowCVSS 2.0No exploitEPSS 1%flir · flir ax8 firmwareMay 24, 2025
- CVE-2025-62668Monitor
Teledyne FLIR AX8 upload.php unrestricted upload
LowCVSS 2.1No exploitEPSS 1%flir · flir ax8 firmwareJun 19, 2025