CVE-2026-55394
published 2026-10-01CVE-2026-55394: Unencrypted traffic in the 802.11 network of Teledyne FLIR Aware2 versions through 6.9.0.2 allows adjacent unauthenticated attackers to intercept, hijack, or…
PriorityP428medium5.3CVSS 4.0
AVAACLATNPRNUINVCLVINVALSCLSINSALEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.11%
1.3th percentile
Unencrypted traffic in the 802.11 network of Teledyne FLIR Aware2 versions through 6.9.0.2 allows adjacent unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FLIR PackBot robots running this software via sniffing or hijacking network traffic.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| teledyne_flir | aware2 | <= 6.9.0.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Unencrypted traffic in the 802.11 network of Teledyne FLIR Aware2 versions through 6.9.0.2 allows adjacent unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FL
ghsa_unreviewed·2026-10-01
CVE-2026-55394 [MEDIUM] CWE-319 Unencrypted traffic in the 802.11 network of Teledyne FLIR Aware2 versions through 6.9.0.2 allows adjacent unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FL
Unencrypted traffic in the 802.11 network of Teledyne FLIR Aware2 versions through 6.9.0.2 allows adjacent unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FLIR PackBot robots running this software via sniffing or hijacking network traffic.
VulDB
Teledyne FLIR Aware2 up to 6.9.0.2 cleartext transmission
vuldb·2026-10-01·CVSS 5.3
CVE-2026-55394 [MEDIUM] Teledyne FLIR Aware2 up to 6.9.0.2 cleartext transmission
A vulnerability has been found in Teledyne FLIR Aware2 up to 6.9.0.2 and classified as problematic. Affected is an unknown function. This manipulation causes cleartext transmission of sensitive information.
This vulnerability is tracked as CVE-2026-55394. The attack is possible to be carried out remotely. No exploit exists.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-10-01
Published