PT-2025-53358 · Flir · Flir Ax8 Firmware

CVE-2018-25138

·

Published

2025-12-24

·

Updated

2025-12-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FLIR AX8 Thermal Camera version 1.32.16
Description The device contains hard-coded SSH and web panel credentials that cannot be modified through standard camera operations. This allows attackers to use predefined username and password combinations to gain unauthorized shell access and log into multiple camera interfaces.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-25138

Affected Products

Flir Ax8 Firmware