CVE-2022-37061 is a critical remote command injection vulnerability affecting FLIR AX8 thermal sensor cameras up to firmware version 1.46.16. An unauthenticated attacker can exploit this by injecting arbitrary shell commands as the root user via the id HTTP POST parameter in the res.php endpoint, leading to full system compromise. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, this flaw presents a severe risk due to its network-based attack vector and low attack complexity. While not listed on the CISA KEV, public exploit modules for Metasploit and Nuclei templates are readily available, and it has received community discussion and media coverage, indicating a high likelihood of exploitation. The vendor has released firmware version 1.49.16 and later to address this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.46.16CPE matchmatch criteria | cpe:2.3:o:flir:flir_ax8_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.