CVE-2018-25137: FLIR Brickstream 3D+ 2.1.742.1842 Unauthenticated Config File Disclosure

Published Dec 24, 2025
·
Updated

FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability in the ExportConfig REST API that allows attackers to download sensitive configuration files. Attackers can exploit the getConfigExportFile.cgi endpoint to retrieve system configurations, potentially enabling authentication bypass and privilege escalation.

Affected Software

1 affected component
FLIR Brickstream 3D+

Event History

Dec 24, 2025
CVE Published
via MITRE·07:27 PM
Data Sourced
via MITRE·07:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2018-25137?

CVE-2018-25137 is considered a medium severity vulnerability due to its potential to expose sensitive configuration files.

2

How do I fix CVE-2018-25137?

To fix CVE-2018-25137, it is recommended to secure the ExportConfig REST API and apply any security patches provided by FLIR.

3

What systems are affected by CVE-2018-25137?

CVE-2018-25137 affects FLIR Brickstream 3D+ version 2.1.742.1842.

4

What type of vulnerability is CVE-2018-25137?

CVE-2018-25137 is an unauthenticated vulnerability that allows unauthorized access to configuration files through the API.

5

What could attackers gain from exploiting CVE-2018-25137?

By exploiting CVE-2018-25137, attackers could gain access to sensitive system configuration files, potentially leading to further exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203