CVE-2025-6266: Teledyne FLIR AX8 upload.php unrestricted upload
A vulnerability was detected in Teledyne FLIR AX8 up to 1.46. Affected by this vulnerability is an unknown functionality of the file /upload.php. Performing manipulation of the argument File results in unrestricted upload. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 1.49.16 addresses this issue. Upgrading the affected component is recommended. The vendor points out: "FLIR AX8 internal web site has been refactored to be able to handle the reported vulnerabilities."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Teledyne FLIR AX8to a version that resolves this vulnerability.Fixed in 1.49.16
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6266?
CVE-2025-6266 has been declared as critical due to its potential impact and exploitability.
What systems are affected by CVE-2025-6266?
CVE-2025-6266 affects FLIR AX8 devices running versions up to and including 1.46.
How can I mitigate CVE-2025-6266?
To mitigate CVE-2025-6266, restrict access to the /upload.php file and implement proper validation for file uploads.
Can CVE-2025-6266 be exploited remotely?
Yes, CVE-2025-6266 allows for remote exploitation through file upload manipulation.
What kind of attack is enabled by CVE-2025-6266?
CVE-2025-6266 enables unrestricted file upload attacks, potentially compromising the affected system.