Teledyne FLIR FB-Series O and FH-Series Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in Teledyne FLIR FB-Series O and FLIR FH-Series ID version 1.3.2.16. The issue arises in the 'sendCommand' function of the 'runcmd.sh' file, where the 'cmd' argument can be manipulated to inject commands. This vulnerability can be exploited remotely, although the exploitation process is considered complex and difficult. Currently, the vulnerable functionality is disabled due to server CGI configuration errors, but it remains a potential risk.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device.

Added: Jul 14, 2025, 6:24 AM
Updated: Jul 14, 2025, 6:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.6
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.