PT-2025-53360 · Undefined · Undefined

Published

2025-12-24

·

Updated

2025-12-24

·

CVE-2018-25140

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to bypass authentication and authorization controls. Attackers can directly modify device configurations, access system information, and potentially initiate denial of service by sending crafted WebSocket messages without authentication.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2018-25140

Affected Products

Undefined