PT-2025-53358 · Flir · Flir Ax8 Firmware

Published

2025-12-24

·

Updated

2025-12-24

·

CVE-2018-25138

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FLIR AX8 Thermal Camera version 1.32.16
Description The device contains hard-coded SSH and web panel credentials that cannot be modified through standard camera operations. This allows attackers to use predefined username and password combinations to gain unauthorized shell access and log into multiple camera interfaces.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2018-25138

Affected Products

Flir Ax8 Firmware