Impact
The vulnerability is an unvalidated pathname handling flaw in the web interface of Teledyne FLIR Aware2, classified as CWE‑22. It permits an unauthenticated attacker to traverse the directory structure and read arbitrary files on the device, including configuration and security parameters stored on the robot. The impact is the disclosure of sensitive information that could aid further attacks, rather than code execution or denial of service.
Affected Systems
Affected systems are Teledyne FLIR Aware2 robots, specifically the PackBot and FirstLook models. The flaw exists in PackBot firmware versions up to and including 6.9.0.2 and in FirstLook firmware versions up to and including 1.7.9. Any installations running these versions without the fix are susceptible.
Risk and Exploitability
The CVSS score of 10 indicates critical severity. EPSS is not available, and the vulnerability is not listed in CISA KEV, but the flaw allows remote unauthenticated exploitation via the publicly exposed web interface. An attacker only needs network access to the robot's web service to construct a path‑traversal request and retrieve configuration files; no additional authentication or privileged state is required. The risk for operators is high due to the potential for extracting credentials, encryption keys, or other sensitive settings.
OpenCVE Enrichment