CVE-2018-25141: FLIR Thermal Traffic Cameras V1.01-0bb5b27 Unauthenticated RTSP Stream Disclosure
FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly retrieve video streams by accessing specific endpoints like /live.mjpeg, /snapshot.jpg, and RTSP streaming URLs without authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25141?
CVE-2018-25141 is considered a high severity vulnerability due to its potential for unauthorized access to live video streams.
How do I fix CVE-2018-25141?
To fix CVE-2018-25141, update the FLIR Thermal Traffic Cameras to the latest firmware version provided by the manufacturer.
What type of vulnerability is CVE-2018-25141?
CVE-2018-25141 is an unauthenticated remote access vulnerability allowing attackers to access camera feeds.
Are all FLIR Thermal Traffic Cameras affected by CVE-2018-25141?
CVE-2018-25141 affects FLIR Thermal Traffic Cameras running version V1.01-0bb5b27 and earlier.
Can CVE-2018-25141 be exploited remotely?
Yes, CVE-2018-25141 can be exploited remotely without requiring user credentials.