FLIR Brickstream 3D+ Unauthenticated Configuration File Download Vulnerability

Vulnerability

A vulnerability exists in the FLIR Brickstream 3D+ version 2.1.742.1842, specifically within the ExportConfig REST API. This unauthenticated vulnerability allows attackers to download sensitive configuration files from the system. Exploiting the getConfigExportFile.cgi endpoint can lead to the retrieval of system configurations, which may facilitate authentication bypass and privilege escalation.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive system information, potentially allowing for authentication bypass and privilege escalation.

Reproduction

The vulnerability can be reproduced by sending a request to the ExportConfig REST API endpoint getConfigExportFile.cgi. This can be done using a tool like curl. The request will return sensitive configuration files that can be downloaded and reviewed.

Added: Dec 24, 2025, 8:50 PM
Updated: Dec 24, 2025, 9:51 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
1.7
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.