Description
Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne FLIR PackBot and FirstLook robots running this software via reading the passwords from the firmware or documentation.
Published: 2026-10-01
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: Remote Unauthenticated Access
Action: Patch Immediately
AI Analysis

Impact

The Aware2 firmware contains hardcoded passwords embedded in the firmware image and occasionally documented. This allows attackers that can reach the robot’s management interface to obtain the credentials without first authenticating, granting full control over configuration and behavior. The weakness corresponds to CWE‑798: Use of Hard‑Coded Credentials.

Affected Systems

Affected products are Teledyne FLIR Aware2 robots, specifically PackBot running version 6.9.0.2 or earlier and FirstLook running 1.7.9 or earlier. The vulnerability exists in the access control layer that checks for authentication before allowing changes.

Risk and Exploitability

The risk is very high: CVSS 9.4, no EPSS data available, and not yet in KEV. Attackers can exploit the flaw from any network that can reach the robot’s controller, making it a remote, unauthenticated attack. Because the credentials are hardcoded, there is no need for prior knowledge of user credentials; any party with network access could read the firmware and recover the passwords, then reconfigure or command the robot.

Generated by OpenCVE AI on October 1, 2026 at 21:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a patched Aware2 version that removes hardcoded passwords.
  • Restrict external network access by placing the robots behind a firewall or requiring VPN access.
  • Immediately disable or close any unused management interfaces and monitor system logs for unauthorized access attempts.

Generated by OpenCVE AI on October 1, 2026 at 21:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne FLIR PackBot and FirstLook robots running this software via reading the passwords from the firmware or documentation.
Title Hardcoded Passwords in Teledyne FLIR Robots running Aware2
Weaknesses CWE-798
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mandiant

Published:

Updated: 2026-10-01T20:25:37.333Z

Reserved: 2026-06-16T19:45:37.214Z

Link: CVE-2026-55395

cve-icon Vulnrichment

Updated: 2026-10-01T20:25:30.355Z

cve-icon NVD

Status : Received

Published: 2026-10-01T21:17:21.830

Modified: 2026-10-01T21:17:21.830

Link: CVE-2026-55395

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:00:17Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials