CVE-2018-25140: FLIR Thermal Traffic Cameras V1.01-0bb5b27 Unauthenticated Websocket Device Manipulation
FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to bypass authentication and authorization controls. Attackers can directly modify device configurations, access system information, and potentially initiate denial of service by sending crafted WebSocket messages without authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25140?
CVE-2018-25140 is considered a critical severity vulnerability due to its potential for unauthenticated device manipulation in FLIR thermal traffic cameras.
How do I fix CVE-2018-25140?
To fix CVE-2018-25140, it is recommended to update the affected FLIR Thermal Traffic Cameras to the latest firmware version that addresses this vulnerability.
What type of vulnerability is CVE-2018-25140?
CVE-2018-25140 is an unauthenticated device manipulation vulnerability associated with the WebSocket implementation in FLIR thermal traffic cameras.
What can attackers do with CVE-2018-25140?
Attackers exploiting CVE-2018-25140 can bypass authentication and authorization controls to modify device configurations and access sensitive system information.
Which devices are affected by CVE-2018-25140?
CVE-2018-25140 affects specific versions of FLIR Thermal Traffic Cameras, particularly those running versions up to V1.01.