Impact
The vulnerability stems from the use of cleartext HTTP for the primary control endpoints of Teledyne FLIR Aware2. Because authentication is not required, a remote attacker can intercept the traffic and perform session hijacking, modify commands, or fully control the PackBot robot. This allows the attacker to steer the robot, cause harm, or exfiltrate sensitive data, thereby compromising confidentiality, integrity, and availability. The attack vector is inferred to be remote interception or hijacking of unencrypted network traffic.
Affected Systems
Teledyne FLIR Aware2 robots running firmware versions through 6.9.0.2 are impacted. This includes any PackBot units running these releases, regardless of whether the robot is on a local or wide‑area network.
Risk and Exploitability
The flaw carries a CVSS score of 9.4, indicating critical risk. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because control traffic is exposed over plain HTTP, a non‑authenticated attacker who can observe or inject traffic can compromise the robot. The exploitation likelihood is significant in environments with weak network segregation or unencrypted traffic.
OpenCVE Enrichment