Description
Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot and FirstLook robots running this software via path traversal.
Published: 2026-10-01
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an unvalidated pathname handling flaw in the web interface of Teledyne FLIR Aware2, classified as CWE‑22. It permits an unauthenticated attacker to traverse the directory structure and read arbitrary files on the device, including configuration and security parameters stored on the robot. The impact is the disclosure of sensitive information that could aid further attacks, rather than code execution or denial of service.

Affected Systems

Affected systems are Teledyne FLIR Aware2 robots, specifically the PackBot and FirstLook models. The flaw exists in PackBot firmware versions up to and including 6.9.0.2 and in FirstLook firmware versions up to and including 1.7.9. Any installations running these versions without the fix are susceptible.

Risk and Exploitability

The CVSS score of 10 indicates critical severity. EPSS is not available, and the vulnerability is not listed in CISA KEV, but the flaw allows remote unauthenticated exploitation via the publicly exposed web interface. An attacker only needs network access to the robot's web service to construct a path‑traversal request and retrieve configuration files; no additional authentication or privileged state is required. The risk for operators is high due to the potential for extracting credentials, encryption keys, or other sensitive settings.

Generated by OpenCVE AI on October 1, 2026 at 21:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Aware2 to a patched release (PackBot version 6.9.0.3 or later, FirstLook 1.7.10 or later).
  • Limit web interface exposure by configuring firewall rules or network segmentation to allow access only from trusted management stations.
  • Review and harden file access permissions on the robot firmware to prevent reading of configuration files from non‑privileged processes.

Generated by OpenCVE AI on October 1, 2026 at 21:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot and FirstLook robots running this software via path traversal.
Title Local File Inclusion in Teledyne FLIR Robots running Aware2
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mandiant

Published:

Updated: 2026-10-01T20:28:55.051Z

Reserved: 2026-06-16T19:45:37.214Z

Link: CVE-2026-55393

cve-icon Vulnrichment

Updated: 2026-10-01T20:28:52.307Z

cve-icon NVD

Status : Received

Published: 2026-10-01T21:17:21.540

Modified: 2026-10-01T21:17:21.540

Link: CVE-2026-55393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:00:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')