Description
Cleartext transmission in the primary control endpoints of Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FLIR PackBot robots running this software via sniffing or hijacking network traffic.
Published: 2026-10-01
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: Remote Session Hijack
Action: Immediate Patch
AI Analysis

Impact

The vulnerability stems from the use of cleartext HTTP for the primary control endpoints of Teledyne FLIR Aware2. Because authentication is not required, a remote attacker can intercept the traffic and perform session hijacking, modify commands, or fully control the PackBot robot. This allows the attacker to steer the robot, cause harm, or exfiltrate sensitive data, thereby compromising confidentiality, integrity, and availability. The attack vector is inferred to be remote interception or hijacking of unencrypted network traffic.

Affected Systems

Teledyne FLIR Aware2 robots running firmware versions through 6.9.0.2 are impacted. This includes any PackBot units running these releases, regardless of whether the robot is on a local or wide‑area network.

Risk and Exploitability

The flaw carries a CVSS score of 9.4, indicating critical risk. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because control traffic is exposed over plain HTTP, a non‑authenticated attacker who can observe or inject traffic can compromise the robot. The exploitation likelihood is significant in environments with weak network segregation or unencrypted traffic.

Generated by OpenCVE AI on October 1, 2026 at 21:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Teledyne FLIR Aware2 to a firmware release that encrypts control traffic (versions newer than 6.9.0.2).
  • Enforce HTTPS or TLS for all robot control endpoints, eliminating cleartext communication channels.
  • Restrict network access to control interfaces by implementing firewall rules or VLAN segmentation, ensuring only trusted devices can reach the robot's control ports.
  • Monitor network traffic for anomalous activity related to robot control commands and implement intrusion detection if possible.

Generated by OpenCVE AI on October 1, 2026 at 21:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description Cleartext transmission in the primary control endpoints of Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FLIR PackBot robots running this software via sniffing or hijacking network traffic.
Title Cleartext HTTP for Control Traffic in Teledyne FLIR Robots running Aware2
Weaknesses CWE-319
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mandiant

Published:

Updated: 2026-10-01T20:16:19.422Z

Reserved: 2026-07-07T17:51:57.310Z

Link: CVE-2026-14984

cve-icon Vulnrichment

Updated: 2026-10-01T20:14:53.529Z

cve-icon NVD

Status : Received

Published: 2026-10-01T20:17:24.297

Modified: 2026-10-01T21:17:20.093

Link: CVE-2026-14984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:00:17Z

Weaknesses
  • CWE-319

    Cleartext Transmission of Sensitive Information