CVE-2018-25138: FLIR AX8 Thermal Camera 1.32.16 Hard-Coded Credentials Authentication Bypass
FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. Attackers can exploit these persistent credentials to gain unauthorized shell access and login to multiple camera interfaces using predefined username and password combinations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25138?
CVE-2018-25138 is considered a high severity vulnerability due to the presence of hard-coded credentials that can lead to unauthorized access.
How do I fix CVE-2018-25138?
To mitigate CVE-2018-25138, consider securing the device by restricting network access and implementing strict firewall rules.
What are the potential impacts of CVE-2018-25138?
Exploitation of CVE-2018-25138 allows attackers to gain unauthorized shell access to the thermal camera, potentially leading to unauthorized control and data breaches.
What devices are affected by CVE-2018-25138?
CVE-2018-25138 affects the FLIR AX8 Thermal Camera with firmware version 1.32.16.
Is there a patch available for CVE-2018-25138?
As of now, there is no patch available for CVE-2018-25138, making it crucial to secure the device through alternative measures.