FLIR Thermal Cameras Unauthenticated Live Stream Access Vulnerability

Vulnerability

A vulnerability in FLIR Thermal Camera firmware version 8.0.0.64 allows remote access to live camera streams without authentication. This issue affects multiple camera series, including the PT-Series, FC-Series S, FC-Series R, D-Series, and F-Series. The vulnerability arises from a lack of proper authentication, enabling unauthorized users to view thermal video feeds over IP networks.

Impact

Exploitation of this vulnerability leads to unauthorized access to live thermal video streams from the affected cameras.

Reproduction

The vulnerability can be reproduced by sending a request to the camera's live video stream endpoint. This can be done using a web browser or a tool like curl, targeting the specific stream URLs mentioned in the advisory.

Remediation

FLIR has released a security patch for this vulnerability. Instructions for applying the patch can be obtained by contacting FLIR's thermal support.

Added: Jan 8, 2026, 12:46 AM
Updated: Jan 8, 2026, 12:46 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
7.7
relevance
1.9
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.