CVE-2025-5695: Teledyne FLIR AX8 Backend subscriptions.php subscribe_to_alarm command injection
A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. This impacts the function subscribetospot/subscribetodelta/subscribetoalarm of the file /usr/www/application/models/subscriptions.php of the component Backend. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.49.16 will fix this issue. It is suggested to upgrade the affected component. The vendor points out: "FLIR AX8 internal web site has been refactored to be able to handle the reported vulnerabilities."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5695?
CVE-2025-5695 is classified as a critical vulnerability.
What component is affected by CVE-2025-5695?
CVE-2025-5695 affects the Backend component of the FLIR AX8 firmware.
How does CVE-2025-5695 impact the FLIR AX8?
CVE-2025-5695 allows for command injection through the subscribe_to_spot, subscribe_to_delta, and subscribe_to_alarm functions.
Which versions of FLIR AX8 are affected by CVE-2025-5695?
CVE-2025-5695 affects FLIR AX8 versions up to and including 1.46.16.
How do I fix CVE-2025-5695?
To mitigate CVE-2025-5695, upgrade the FLIR AX8 firmware to a version beyond 1.46.16.