cbcvebase.

Teledyne Flir Aware2 vulnerabilities

6 known vulnerabilities affecting teledyne_flir/aware2.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2026-55393P2CRITICALCVSS 10.0≤ 6.9.0.22026-10-01
CVE-2026-55393 [CRITICAL] CWE-22 CVE-2026-55393: Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot and FirstLook robots running this software via path traversal.
nvd
CVE-2026-55395P3CRITICALCVSS 9.4≤ 6.9.0.22026-10-01
CVE-2026-55395 [CRITICAL] CWE-798 CVE-2026-55395: Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne FLIR PackBot and FirstLook robots running this software via reading the passwords from the firmware or documentation.
nvd
CVE-2026-14984P3CRITICALCVSS 9.4≤ 6.9.0.22026-10-01
CVE-2026-14984 [CRITICAL] CWE-319 CVE-2026-14984: Cleartext transmission in the primary control endpoints of Teledyne FLIR Aware2 versions through 6.9 Cleartext transmission in the primary control endpoints of Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FLIR PackBot robots running this software via sniffing or hijacking network traffic.
nvd
CVE-2026-55396P3HIGHCVSS 8.5≤ 6.9.0.22026-10-01
CVE-2026-55396 [HIGH] CWE-319 CVE-2026-55396: Cleartext transmission without a cryptographic integrity check in operator control unit to robot UDP Cleartext transmission without a cryptographic integrity check in operator control unit to robot UDP traffic in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows adjacent unauthenticated attackers to intercept, hijack, or modify control traffic against Teledyne FLIR PackBot and FirstLook robots running this software
nvd
CVE-2026-14983P3HIGHCVSS 7.1≤ 6.9.0.22026-10-01
CVE-2026-14983 [HIGH] CWE-306 CVE-2026-14983: Missing authentication in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 allows Missing authentication in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to achieve denial of service against Teledyne FLIR PackBot robots running this software via misuse of the reboot endpoint.
nvd
CVE-2026-55394P4MEDIUMCVSS 5.3≤ 6.9.0.22026-10-01
CVE-2026-55394 [MEDIUM] CWE-319 CVE-2026-55394: Unencrypted traffic in the 802.11 network of Teledyne FLIR Aware2 versions through 6.9.0.2 allows ad Unencrypted traffic in the 802.11 network of Teledyne FLIR Aware2 versions through 6.9.0.2 allows adjacent unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FLIR PackBot robots running this software via sniffing or hijacking network traffic.
nvd
Teledyne Flir Aware2 vulnerabilities | cvebase