Description
Missing authentication in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to achieve denial of service against Teledyne FLIR PackBot robots running this software via misuse of the reboot endpoint.
Published: 2026-10-01
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The flaw is a lack of authentication control on the web interface of Teledyne FLIR Aware2. It allows any remote user to call the robot’s reboot endpoint without first authenticating. When the reboot endpoint is invoked, the PackBot robot restarts, causing a temporary loss of operation. The vulnerability is an authentication bypass (CWE-306) and results in a local denial of service: the affected robot becomes unavailable until the reboot cycle completes. No evidence is provided that the flaw affects confidentiality or integrity, only availability.

Affected Systems

Teledyne FLIR Aware2 software built into PackBot robots, specifically versions through 6.9.0.2, are affected. Any PackBot running these or earlier versions without the fix can be remotely accessed by unauthenticated attackers.

Risk and Exploitability

With a CVSS score of 7.1 the vulnerability is classified as high severity. EPSS data is not available and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote interaction with the device’s web interface, where an attacker, without credentials, can hit the unsecured reboot endpoint. The simplicity of the interaction and lack of defensive controls makes exploitation straightforward for anyone with network connectivity to the robot.

Generated by OpenCVE AI on October 1, 2026 at 21:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Aware2 firmware to a version later than 6.9.0.2 where the reboot endpoint is protected by authentication.
  • Restrict network access to the PackBot web interface via firewall or network segmentation so that only trusted hosts can reach it.
  • Enable detailed logging and monitor for repeated, abnormal reboot requests to detect potential exploitation attempts.

Generated by OpenCVE AI on October 1, 2026 at 21:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description Missing authentication in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to achieve denial of service against Teledyne FLIR PackBot robots running this software via misuse of the reboot endpoint.
Title Missing Authentication in Teledyne FLIR Robots running Aware2
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mandiant

Published:

Updated: 2026-10-01T20:13:53.282Z

Reserved: 2026-07-07T17:51:56.724Z

Link: CVE-2026-14983

cve-icon Vulnrichment

Updated: 2026-10-01T20:13:48.016Z

cve-icon NVD

Status : Received

Published: 2026-10-01T20:17:24.167

Modified: 2026-10-01T21:17:19.957

Link: CVE-2026-14983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:00:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function