FLIR Thermal Camera FC-S/PT Authenticated OS Command Injection Vulnerability

Vulnerability

An authenticated OS command injection vulnerability has been identified in the FLIR Thermal Camera FC-S/PT, specifically in firmware version 8.0.0.64. This vulnerability allows authenticated attackers to execute arbitrary shell commands with root privileges, thereby gaining complete control over the thermal camera system. The issue arises from unvalidated input parameters that can be exploited to inject commands into the operating system.

Impact

Exploitation of this vulnerability allows for authenticated users to execute arbitrary commands as the root user on the affected device.

Reproduction

The vulnerability can be reproduced by sending a POST request to the '/page/maintenance/lanSettings/dns' endpoint. The request must include a 'PHPSESSID' cookie for session management. Within the body of the request, arbitrary shell commands can be injected through the 'dns[server2]' parameter. The injected command is executed on the server, allowing for command injection exploitation.

Remediation

Users are advised to contact FLIR thermal support for guidance on applying the security patch v1.1, released on October 9, 2017.

Added: Jan 8, 2026, 12:43 AM
Updated: Jan 8, 2026, 12:43 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.6
remediation
7.7
relevance
1.9
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.