Description
FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly connect to the RTSP stream using tools like VLC or FFmpeg to view and record thermal camera footage.
Published: 2025-12-24
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 31 Dec 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Flir flir Ax8 Firmware
CPEs cpe:2.3:h:flir:flir_ax8:-:*:*:*:*:*:*:*
cpe:2.3:o:flir:flir_ax8_firmware:1.17.13:*:*:*:*:*:*:*
cpe:2.3:o:flir:flir_ax8_firmware:1.32.16:*:*:*:*:*:*:*
Vendors & Products Flir flir Ax8 Firmware

Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Flir
Flir flir Ax8
Vendors & Products Flir
Flir flir Ax8

Wed, 24 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Dec 2025 19:45:00 +0000

Type Values Removed Values Added
Description FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly connect to the RTSP stream using tools like VLC or FFmpeg to view and record thermal camera footage.
Title FLIR AX8 Thermal Camera 1.32.16 Unauthenticated RTSP Stream Disclosure
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Flir Flir Ax8 Flir Ax8 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-24T20:26:15.968Z

Reserved: 2025-12-24T14:28:02.434Z

Link: CVE-2018-25139

cve-icon Vulnrichment

Updated: 2025-12-24T20:12:49.024Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-24T20:15:47.957

Modified: 2025-12-31T18:40:36.483

Link: CVE-2018-25139

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-29T23:04:29Z

Weaknesses