FLIR AX8
cpe:2.3:h:flir:flir_ax8:*:*:*:*:*:*:*, +1 more
- <= 1.46.16
A critical command injection vulnerability has been identified in the FLIR AX8 camera, affecting versions through 1.46.16. The issue arises in the 'setDataTime' function within the 'settingsregional.php' file, where improper handling of the 'year', 'month', 'day', 'hour', and 'minute' parameters allows for remote command injection. This vulnerability has been publicly disclosed and is actively exploitable.
Exploitation of this vulnerability allows for remote command injection, where an attacker can execute arbitrary commands on the server where the FLIR AX8 is hosted.
The vulnerability can be reproduced by sending a request to the 'settingsregional.php' file with manipulated 'year', 'month', 'day', 'hour', and 'minute' parameters. This can be done remotely, and the exploitation appears to be straightforward.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.