Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Flir

First CVE: Jan 1, 2018Active for: 9 yearsTotal CVEs: 17
55.9
VTI Score
TOP TARGET

Flir manufactures thermal imaging and video analytics hardware, including the AX8 thermal camera and Brickstream occupancy-sensing line, which are deployed in building security, facility monitoring, and access-control environments. Vulnerabilities affecting the vendor skew strongly toward critical severity and cluster around command injection, code injection, and path traversal flaws in device firmware and management interfaces—weakness classes endemic to embedded systems with network accessibility and privilege boundaries. Defenders should treat firmware updates for these imaging and analytics devices as security-critical; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Flir over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 2018
8 years ago
Most Recent CVE
Dec 24, 2025
212 days ago

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-37061CRITICAL
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell comm
Aug 18, 20229.894NOYES
CVE-2023-51126CRITICAL
Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter. NOTE: The vendor has stated that w
Jan 10, 20249.846NONO
CVE-2018-25138CRITICAL
FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. Attackers can exploit these persistent cr
Dec 24, 20259.834NONO
CVE-2024-3013HIGH
A flaw has been found in Teledyne FLIR AX8 up to 1.46.16. The impacted element is an unknown function of the file /tools/test_login.php?action=register of the component User Regist
Mar 28, 20248.832NONO
CVE-2022-4364CRITICAL
A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of the component Web Service Handler
Dec 8, 20229.832NONO
CVE-2022-37060HIGH
FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access restriction. An unauthenticated, remote attacker
Aug 18, 20227.532NONO
CVE-2023-29861CRITICAL
An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of the device.
May 15, 20239.830NONO
CVE-2018-3813CRITICAL
getConfigExportFile.cgi on FLIR Brickstream 2300 devices 2.0 4.1.53.166 has Incorrect Access Control, as demonstrated by reading the AVI_USER_ID and AVI_USER_PASSWORD fields via a
Jan 1, 20189.829NONO
CVE-2025-5126HIGH
A vulnerability was found in Teledyne FLIR AX8 up to 1.46.16. This vulnerability affects the function setDataTime of the file \usr\www\application\models\settingsregional.php. Perf
May 24, 20258.827NONO
CVE-2025-6266CRITICAL
A vulnerability was detected in Teledyne FLIR AX8 up to 1.46. Affected by this vulnerability is an unknown functionality of the file /upload.php. Performing manipulation of the arg
Jun 19, 20259.826NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
18%
41%
41%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (88.2%)
Unknown0 (0.0%)
Required2 (11.8%)
Privileges Required
Low4 (23.5%)
High1 (5.9%)
None12 (70.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
5.9% of CVEs· 98th percentile
Nuclei
1 CVE
5.9% of CVEs· 96th percentile
ExploitDB
1 CVE
5.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Flir.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Flir — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Flir's Products

View all 3 CNAs →

Top CWEs