FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to bypass authentication and authorization controls. Attackers can directly modify device configurations, access system information, and potentially initiate denial of service by sending crafted WebSocket messages without authentication.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-12-24 20:15
Updated : 2025-12-29 15:58
NVD link : CVE-2018-25140
Mitre link : CVE-2018-25140
CVE.ORG link : CVE-2018-25140
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
