Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

FLIR Thermal Traffic Cameras WebSocket Unauthenticated Device Manipulation Vulnerability

Vulnerability

A vulnerability allowing unauthenticated manipulation of device settings has been identified in FLIR thermal traffic cameras. This issue arises from an insecure implementation of WebSocket communication in various models, including TrafiOne, ThermiCam, TrafiSense, and others. The vulnerability allows attackers to bypass authentication and authorization, directly alter device configurations, access sensitive system information, and potentially cause a denial-of-service by sending crafted WebSocket messages. Additionally, the lack of support for secure WebSocket connections exposes plain-text traffic to potential interception.

Impact

Exploitation of this vulnerability could lead to unauthorized modification of device settings, disclosure of sensitive system information, and initiation of a denial-of-service condition by causing the device to reboot.

Reproduction

The vulnerability can be reproduced by establishing a WebSocket connection to the device's WebSocket endpoint without authentication. Once connected, an attacker can send messages to the device that correspond to various command types recognized by the WebSocket API. This includes messages that can alter device settings or initiate a reboot, thereby causing a denial-of-service condition.

Remediation

FLIR has released firmware updates to address this vulnerability. Instructions for applying the update can be found on the FLIR website.

Added: Dec 24, 2025, 8:47 PM
Updated: Dec 24, 2025, 9:49 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
9.1
remediation
7.7
relevance
1.7
threat
8.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.