CVE-2018-25137

FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability in the ExportConfig REST API that allows attackers to download sensitive configuration files. Attackers can exploit the getConfigExportFile.cgi endpoint to retrieve system configurations, potentially enabling authentication bypass and privilege escalation.
Configurations

No configuration.

History

No history.

Information

Published : 2025-12-24 20:15

Updated : 2025-12-29 15:58


NVD link : CVE-2018-25137

Mitre link : CVE-2018-25137

CVE.ORG link : CVE-2018-25137


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function