Impact
The Aware2 firmware contains hardcoded passwords embedded in the firmware image and occasionally documented. This allows attackers that can reach the robot’s management interface to obtain the credentials without first authenticating, granting full control over configuration and behavior. The weakness corresponds to CWE‑798: Use of Hard‑Coded Credentials.
Affected Systems
Affected products are Teledyne FLIR Aware2 robots, specifically PackBot running version 6.9.0.2 or earlier and FirstLook running 1.7.9 or earlier. The vulnerability exists in the access control layer that checks for authentication before allowing changes.
Risk and Exploitability
The risk is very high: CVSS 9.4, no EPSS data available, and not yet in KEV. Attackers can exploit the flaw from any network that can reach the robot’s controller, making it a remote, unauthenticated attack. Because the credentials are hardcoded, there is no need for prior knowledge of user credentials; any party with network access could read the firmware and recover the passwords, then reconfigure or command the robot.
OpenCVE Enrichment