PT-2025-22841 · Flir · Flir Ax8

Xu17

·

Published

2025-05-24

·

Updated

2025-06-16

·

CVE-2025-5126

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FLIR AX8 versions up to 1.46.16
Description A critical vulnerability was found in FLIR AX8, affecting the setDataTime function of the file usrwwwapplicationmodelssettingsregional.php. The manipulation of the arguments year, month, day, hour, and minute leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Recommendations For FLIR AX8 versions up to 1.46.16, as a temporary workaround, consider disabling the setDataTime function until a patch is available. Restrict access to the vulnerable file usrwwwapplicationmodelssettingsregional.php to minimize the risk of exploitation. Avoid using the arguments year, month, day, hour, and minute in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-5126

Affected Products

Flir Ax8