CVE-2017-20215
8.8FLIR Systems · Thermal Camera FC-S/PT
FLIR Thermal Camera FC-S/PT firmware 8.0.0.64 contains an authenticated OS command injection vulnerability, allowing remote attackers to execute arbitrary shell commands with root privileges.
Executive summary
An authenticated OS command injection vulnerability in FLIR Thermal Camera FC-S/PT firmware allows an attacker to gain full root-level control of the device.
Vulnerability
The device suffers from an OS command injection flaw triggered via unvalidated input in the maintenance/lanSettings/dns endpoint. An authenticated attacker can inject malicious shell commands into the dns[server2] parameter to achieve code execution with root privileges.
Business impact
Successful exploitation grants an attacker complete control over the affected thermal camera. This compromise can lead to unauthorized surveillance, the exfiltration of sensitive video data, or the use of the camera as a pivot point for further lateral movement within the internal network. Given the CVSS score of 8.8, this represents a high-severity risk to operational security and network integrity.
Remediation
Immediate Action: Contact FLIR Systems support to obtain the latest firmware update, as no public patch version is specified for this legacy vulnerability.
Proactive Monitoring: Monitor network traffic for unusual outbound connections originating from camera management interfaces and audit device access logs for suspicious administrative activity.
Compensating Controls: Restrict access to the camera management interface to trusted administrative IP addresses only, and employ a Web Application Firewall to filter malicious patterns in HTTP POST requests.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exploit is available via ExploitDB (EDB-ID: 42788) and Packet Storm Security.
Analyst recommendation
Given the availability of public exploit code and the high impact of root-level command injection, administrators must prioritize securing these devices. If firmware updates are unavailable, the devices should be isolated from the general network using VLANs or strict firewall rules to prevent unauthorized access to the management interface.
More FLIR Systems CVEs
Sources
Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.
- Zero Science Lab Vulnerability Advisory Third-party advisory
- Exploit Database Entry 42788 Exploit / PoC
- Packet Storm Security Exploit Archive Exploit / PoC
- CXSecurity Vulnerability Listing Third-party advisory
- Archived FLIR Security Advisory Vendor advisory