Advisories

FLIR AX8 Thermal Camera 1.32.16 Hard-Coded Credentials Authentication Bypass

Go Back
severity
critical
date
Affecting
  • FLIR AX8 Thermal Camera 1.32.16

CWE
  • CWE-798 Use of Hard-coded Credentials
CVSS
9.3
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
LiquidWorm as Gjoko Krstic of Zero Science Lab
Description
FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. Attackers can exploit these persistent credentials to gain unauthorized shell access and login to multiple camera interfaces using predefined username and password combinations.