Flir manufactures thermal imaging and video analytics hardware, including the AX8 thermal camera and Brickstream occupancy-sensing line, which are deployed in building security, facility monitoring, and access-control environments. Vulnerabilities affecting the vendor skew strongly toward critical severity and cluster around command injection, code injection, and path traversal flaws in device firmware and management interfaces—weakness classes endemic to embedded systems with network accessibility and privilege boundaries. Defenders should treat firmware updates for these imaging and analytics devices as security-critical; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flir over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37061CRITICAL All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell comm | Aug 18, 2022 | 9.8 | 94 | NO | YES |
CVE-2023-51126CRITICAL Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter. NOTE: The vendor has stated that w | Jan 10, 2024 | 9.8 | 46 | NO | NO |
CVE-2018-25138CRITICAL FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. Attackers can exploit these persistent cr | Dec 24, 2025 | 9.8 | 34 | NO | NO |
CVE-2024-3013HIGH A flaw has been found in Teledyne FLIR AX8 up to 1.46.16. The impacted element is an unknown function of the file /tools/test_login.php?action=register of the component User Regist | Mar 28, 2024 | 8.8 | 32 | NO | NO |
CVE-2022-4364CRITICAL A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of the component Web Service Handler | Dec 8, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-37060HIGH FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access restriction. An unauthenticated, remote attacker | Aug 18, 2022 | 7.5 | 32 | NO | NO |
CVE-2023-29861CRITICAL An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of the device. | May 15, 2023 | 9.8 | 30 | NO | NO |
CVE-2018-3813CRITICAL getConfigExportFile.cgi on FLIR Brickstream 2300 devices 2.0 4.1.53.166 has Incorrect Access Control, as demonstrated by reading the AVI_USER_ID and AVI_USER_PASSWORD fields via a | Jan 1, 2018 | 9.8 | 29 | NO | NO |
CVE-2025-5126HIGH A vulnerability was found in Teledyne FLIR AX8 up to 1.46.16. This vulnerability affects the function setDataTime of the file \usr\www\application\models\settingsregional.php. Perf | May 24, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-6266CRITICAL A vulnerability was detected in Teledyne FLIR AX8 up to 1.46. Affected by this vulnerability is an unknown functionality of the file /upload.php. Performing manipulation of the arg | Jun 19, 2025 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flir.
Media articles that mention a CVE ID that affects a product developed by Flir — matched by CVE ID, not by vendor name.