Impact
The flaw is a lack of authentication control on the web interface of Teledyne FLIR Aware2. It allows any remote user to call the robot’s reboot endpoint without first authenticating. When the reboot endpoint is invoked, the PackBot robot restarts, causing a temporary loss of operation. The vulnerability is an authentication bypass (CWE-306) and results in a local denial of service: the affected robot becomes unavailable until the reboot cycle completes. No evidence is provided that the flaw affects confidentiality or integrity, only availability.
Affected Systems
Teledyne FLIR Aware2 software built into PackBot robots, specifically versions through 6.9.0.2, are affected. Any PackBot running these or earlier versions without the fix can be remotely accessed by unauthenticated attackers.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is classified as high severity. EPSS data is not available and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote interaction with the device’s web interface, where an attacker, without credentials, can hit the unsecured reboot endpoint. The simplicity of the interaction and lack of defensive controls makes exploitation straightforward for anyone with network connectivity to the robot.
OpenCVE Enrichment