FLIR Thermal Camera F/FC/PT/D Stream firmware version 8
Description
FLIR Thermal Camera F/FC/PT/D Stream firmware version 8
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: FLIR Systems
PRODUCT: Thermal Camera F/FC/PT/D Series
AFFECTED_VERSIONS: 8.0.0.64
CONFIDENCE: high
MISSING: none
CREDITS: LiquidWorm as Gjoko Krstic of Zero Science Lab (finder)
SOURCES_JSON: [{"url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5435.php","name":"Zero Science Lab Vulnerability Advisory","tags":["third-party-advisory"]},{"url":"https://www.exploit-db.com/exploits/42789/","name":"Exploit Database Entry 42789","tags":["exploit"]},{"url":"https://packetstormsecurity.com/files/144323","name":"Packet Storm Security Exploit Archive","tags":["exploit"]},{"url":"https://cxsecurity.com/issue/WLB-2017090204","name":"CXSecurity Vulnerability Listing","tags":["third-party-advisory"]},{"url":"https://web.archive.org/web/20171011125811/https://www.flir.com/security/blog/details/?ID=87043","name":"Archived FLIR Security Advisory","tags":["vendor-advisory","patch"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T14:11:36.258Z
---END_METADATA---
Description Summary:
FLIR Thermal Camera F/FC/PT/D series firmware version 8.0.0.64 allows unauthenticated remote attackers to access live camera streams without credentials.
Executive Summary:
A critical authentication bypass vulnerability in FLIR thermal cameras allows unauthorized parties to view live video feeds remotely without valid credentials.
Vulnerability Details
CVE-ID: CVE-2017-20213
Affected Software: FLIR Systems, Thermal Camera F/FC/PT/D Series
Affected Versions: 8.0.0.64
Vulnerability: The device suffers from a missing authentication for critical function (CWE-306), which allows an unauthenticated attacker to access the live video stream by requesting specific endpoints on the device web server.
Business Impact
The ability for unauthorized parties to view live thermal video feeds poses a significant risk to physical security, privacy, and operational integrity. Given the 7.5 CVSS score, this vulnerability represents a high risk to organizations that rely on these cameras for surveillance, as it effectively renders existing access control mechanisms useless for the video stream.
Remediation Plan
Immediate Action: Update the affected FLIR camera firmware to the latest version provided by the vendor to resolve the authentication bypass.
Proactive Monitoring: Review web server and network access logs for suspicious requests targeting the /graphics/livevideo/stream/ path, which is known to be the vulnerable endpoint.
Compensating Controls: If an immediate update is not feasible, isolate the affected camera management interfaces from public networks using a firewall or VPN to restrict access to authorized personnel only.
Exploitation Status
Public Exploit Available: Yes, a published proof of concept exists via ExploitDB (EDB-ID: 42789) and Packet Storm Security.
Analyst Notes: As of January 9, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment, a proof of concept exists, so exploitation risk should be treated as credible. The vulnerability is highly accessible as it does not require any specialized knowledge or interaction to trigger.
Analyst Recommendation
This vulnerability presents a clear risk to physical security deployments. It is imperative that administrators identify all vulnerable FLIR camera units within their environment and apply the necessary firmware updates immediately. If patching cannot be performed, network-level segmentation is required to prevent unauthorized access to these video streams.