CVE-2018-25139

FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly connect to the RTSP stream using tools like VLC or FFmpeg to view and record thermal camera footage.
References
Link Resource
https://www.exploit-db.com/exploits/45606 Exploit Third Party Advisory VDB Entry
https://www.flir.com Product
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5492.php Exploit Third Party Advisory
https://www.exploit-db.com/exploits/45606 Exploit Third Party Advisory VDB Entry
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5492.php Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:flir:flir_ax8_firmware:1.32.16:*:*:*:*:*:*:*
cpe:2.3:h:flir:flir_ax8:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:flir:flir_ax8_firmware:1.17.13:*:*:*:*:*:*:*
cpe:2.3:h:flir:flir_ax8:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-24 20:15

Updated : 2025-12-31 18:40


NVD link : CVE-2018-25139

Mitre link : CVE-2018-25139

CVE.ORG link : CVE-2018-25139


JSON object : View

Products Affected

flir

  • flir_ax8_firmware
  • flir_ax8
CWE
CWE-306

Missing Authentication for Critical Function