Actively Exploited in the Wild
This vulnerability is being actively exploited in the wild.
FLIR Systems FLIR Thermal Camera F/FC/PT/D Hard-Coded SSH Credentials
Vulnerability
A vulnerability exists in FLIR Thermal Cameras in the F, FC, PT, and D series, specifically in firmware version 8.0.0.64. The issue stems from hard-coded SSH credentials embedded in the camera's Linux distribution, which cannot be altered through standard camera operations. This flaw allows unauthorized remote access to the camera system.
Impact
Exploitation of this vulnerability provides unauthorized remote access to the affected thermal camera system.
Remediation
FLIR has released a security patch for this vulnerability. Instructions for applying the patch can be obtained by contacting FLIR's thermal support at product.thermal.support@flir.com.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
