CVE-2023-51127: Path Traversal
FLIR AX8 thermal sensor cameras up to and including 1.46.16 are vulnerable to Directory Traversal due to improper access restriction. This vulnerability allows an unauthenticated, remote attacker to obtain arbitrary sensitive file contents by uploading a specially crafted symbolic link file. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51127?
CVE-2023-51127 is considered a critical vulnerability due to the potential for unauthorized access to sensitive files.
How do I fix CVE-2023-51127?
To remediate CVE-2023-51127, update the FLIR AX8 thermal sensor camera firmware to a version above 1.46.16.
Who is affected by CVE-2023-51127?
CVE-2023-51127 affects users of FLIR AX8 thermal sensor cameras running firmware version 1.46.16 and below.
What type of attack is possible through CVE-2023-51127?
CVE-2023-51127 allows unauthenticated remote attackers to perform a directory traversal attack to access arbitrary sensitive files.
Is authentication required to exploit CVE-2023-51127?
No, CVE-2023-51127 can be exploited by an unauthenticated attacker, making it particularly dangerous.