Skip to content
Noroxi

FLIR records

17 published records for vendor flir.

All records

17 records
  • CVE-2022-37061
    69This week

    All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection.

    CriticalCVSS 9.8WeaponizedEPSS 100%

    flir · flir ax8 firmwareAug 18, 2022

  • Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value param

    CriticalCVSS 9.8Proof of conceptEPSS 31%

    flir · flir ax8 firmwareJan 10, 2024

  • An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the managemen

    CriticalCVSS 9.8No exploitEPSS 2%

    flir · dvtel camera firmwareMay 15, 2023

  • CVE-2018-3813
    39Monitor

    getConfigExportFile.cgi on FLIR Brickstream 2300 devices 2.0 4.1.53.166 has Incorrect Access Control, as demonstrated by reading the AVI_USE

    CriticalCVSS 9.8No exploitEPSS 1%

    flir · brickstream 2300 2d firmwareJan 1, 2018

  • FLIR AX8 Thermal Camera 1.32.16 Hard-Coded Credentials Authentication Bypass

    CriticalCVSS 9.3No exploitEPSS 1%

    flir · flir ax8 firmwareDec 24, 2025

  • FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access restricti

    HighCVSS 7.5No exploitEPSS 18%

    flir · flir ax8 firmwareAug 18, 2022

  • FLIR AX8 Thermal Camera 1.32.16 Unauthenticated RTSP Stream Disclosure

    HighCVSS 8.7No exploitEPSS 1%

    flir · flir ax8 firmwareDec 24, 2025

  • All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability due to an improper

    HighCVSS 7.5No exploitEPSS 3%

    flir · flir ax8 firmwareAug 18, 2022

  • Brickstream 2300 devices allow remote attackers to obtain potentially sensitive information via a direct request for the basic.html#ipsettin

    HighCVSS 7.5No exploitEPSS 2%

    flir · brickstream 2300 firmwareJun 28, 2018

  • CVE-2025-5126
    30Monitor

    Teledyne FLIR AX8 settingsregional.php setDataTime command injection

    HighCVSS 7.4No exploitEPSS 5%

    flir · flir ax8 firmwareMay 24, 2025

  • FLIR AX8 thermal sensor cameras up to and including 1.46.16 are vulnerable to Directory Traversal due to improper access restriction.

    HighCVSS 7.5Proof of conceptEPSS 1%

    flir · flir ax8 firmwareJan 10, 2024

  • CVE-2022-4364
    23Monitor

    Teledyne FLIR AX8 Web Service palette.php command injection

    MediumCVSS 5.5No exploitEPSS 4%

    flir · flir ax8 firmwareDec 8, 2022

  • All FLIR AX8 thermal sensor cameras versions up to and including 1.46.16 are vulnerable to Cross Site Scripting (XSS) due to improper input

    MediumCVSS 5.4No exploitEPSS 2%

    flir · flir ax8 firmwareAug 18, 2022

  • CVE-2024-3013
    15Monitor

    Teledyne FLIR AX8 User Registration test_login.php improper authorization

    LowCVSS 2.1No exploitEPSS 23%

    flir · flir ax8 firmwareMar 27, 2024

  • CVE-2025-5695
    10Monitor

    Teledyne FLIR AX8 Backend subscriptions.php subscribe_to_alarm command injection

    LowCVSS 2.0No exploitEPSS 7%

    flir · flir ax8 firmwareJun 5, 2025

  • Teledyne FLIR AX8 prod.php cross site scripting

    LowCVSS 2.0No exploitEPSS 1%

    flir · flir ax8 firmwareMay 24, 2025

  • Teledyne FLIR AX8 upload.php unrestricted upload

    LowCVSS 2.1No exploitEPSS 1%

    flir · flir ax8 firmwareJun 19, 2025