CVE-2023-51126: Command Injection
Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51126?
CVE-2023-51126 is classified as a high severity command injection vulnerability.
How do I fix CVE-2023-51126?
To fix CVE-2023-51126, upgrade the FLIR AX8 firmware to a version higher than 1.46.16.
What is the impact of CVE-2023-51126?
CVE-2023-51126 allows attackers to execute arbitrary commands on the affected FLIR AX8 devices.
Which FLIR AX8 firmware versions are affected by CVE-2023-51126?
FLIR AX8 firmware versions up to and including 1.46.16 are affected by CVE-2023-51126.
How can attackers exploit CVE-2023-51126?
Attackers can exploit CVE-2023-51126 by manipulating the value parameter in the /usr/www/res.php file.