Impact
The vulnerability exists in Teledyne FLIR Aware2 versions through 6.9.0.2, where the 802.11 wireless network traffic is transmitted without encryption. An attacker who is adjacent to the robot’s Wi‑Fi network can perform passive sniffing or active hijacking, allowing them to intercept, modify, or inject session data sent to or from the PackBot robots. This can result in compromised confidentiality and integrity of control commands and telemetry.
Affected Systems
Devices running Teledyne FLIR Aware2 firmware up to and including version 6.9.0.2 on PackBot robots. The affected component is the Wi‑Fi interface that handles 802.11 network traffic.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate overall risk. Because the EPSS score is not available, the current probability of exploitation is uncertain, but the threat is not in the CISA KEV catalog. The likely attack vector is proximity Wi‑Fi sniffing or hijacking, which does not require any attacker authentication. The impact includes potential unauthorized control of the robot and tampering with sensor data, exposing operational and possibly sensitive information.
OpenCVE Enrichment