CVE-2026-55395
published 2026-10-01CVE-2026-55395: Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated…
PriorityP359critical9.4CVSS 4.0
AVAACLATNPRNUINVCHVIHVAHSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.18%
7.3th percentile
Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne FLIR PackBot and FirstLook robots running this software via reading the passwords from the firmware or documentation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| teledyne_flir | aware2 | <= 6.9.0.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Teledyne FLIR Aware2 up to 1.7.9/6.9.0.2 hard-coded password
vuldb·2026-10-01·CVSS 9.4
CVE-2026-55395 [CRITICAL] Teledyne FLIR Aware2 up to 1.7.9/6.9.0.2 hard-coded password
A vulnerability, which was classified as very critical, was found in Teledyne FLIR Aware2 up to 1.7.9/6.9.0.2. This impacts an unknown function. The manipulation results in use of hard-coded password.
This vulnerability is identified as CVE-2026-55395. The attack can be executed remotely. There is not any exploit available.
GHSA
Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne FL
ghsa_unreviewed·2026-10-01
CVE-2026-55395 [CRITICAL] CWE-798 Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne FL
Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne FLIR PackBot and FirstLook robots running this software via reading the passwords from the firmware or documentation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-10-01
Published