Description
Unencrypted traffic in the 802.11 network of Teledyne FLIR Aware2 versions through 6.9.0.2 allows adjacent unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FLIR PackBot robots running this software via sniffing or hijacking network traffic.
Published: 2026-10-01
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unsecured network traffic causing session hijack and data modification
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in Teledyne FLIR Aware2 versions through 6.9.0.2, where the 802.11 wireless network traffic is transmitted without encryption. An attacker who is adjacent to the robot’s Wi‑Fi network can perform passive sniffing or active hijacking, allowing them to intercept, modify, or inject session data sent to or from the PackBot robots. This can result in compromised confidentiality and integrity of control commands and telemetry.

Affected Systems

Devices running Teledyne FLIR Aware2 firmware up to and including version 6.9.0.2 on PackBot robots. The affected component is the Wi‑Fi interface that handles 802.11 network traffic.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate overall risk. Because the EPSS score is not available, the current probability of exploitation is uncertain, but the threat is not in the CISA KEV catalog. The likely attack vector is proximity Wi‑Fi sniffing or hijacking, which does not require any attacker authentication. The impact includes potential unauthorized control of the robot and tampering with sensor data, exposing operational and possibly sensitive information.

Generated by OpenCVE AI on October 1, 2026 at 21:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Aware2 firmware upgrade that secures Wi‑Fi traffic
  • Configure the robot to use encrypted Wi‑Fi (e.g., WPA2 or WPA3) or disable the unencrypted SSID
  • Segregate the robot’s network segment and monitor for suspicious traffic

Generated by OpenCVE AI on October 1, 2026 at 21:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description Unencrypted traffic in the 802.11 network of Teledyne FLIR Aware2 versions through 6.9.0.2 allows adjacent unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FLIR PackBot robots running this software via sniffing or hijacking network traffic.
Title Unencrypted 802.11 Network in Teledyne FLIR Robots running Aware2
Weaknesses CWE-319
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:L/SI:N/SA:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mandiant

Published:

Updated: 2026-10-01T20:26:08.550Z

Reserved: 2026-06-16T19:45:37.214Z

Link: CVE-2026-55394

cve-icon Vulnrichment

Updated: 2026-10-01T20:25:59.195Z

cve-icon NVD

Status : Received

Published: 2026-10-01T21:17:21.683

Modified: 2026-10-01T21:17:21.683

Link: CVE-2026-55394

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:00:17Z

Weaknesses
  • CWE-319

    Cleartext Transmission of Sensitive Information