FLIR AX8
cpe:2.3:h:flir:flir_ax8:*:*:*:*:*:*:*, +1 more
- 1.32.16
- 1.17.13
- neco_v1.8-0-g7ffe5b3
A vulnerability exists in the FLIR AX8 Thermal Camera running firmware 1.32.16, due to hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. These persistent credentials can be exploited by attackers to gain unauthorized shell access or to log into various camera interfaces using default username and password combinations.
Exploitation of this vulnerability allows for unauthorized shell access on the camera, as well as access to the camera's web interface using default credentials. According to FLIR, this vulnerability could also lead to a denial-of-service.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.