CVE-2018-25136
7.5FLIR Systems · Brickstream 3D+
The FLIR Brickstream 3D+ sensor contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials via direct access to image endpoints.
Executive summary
A critical vulnerability in the FLIR Brickstream 3D+ sensor allows unauthenticated remote attackers to access live video streams, posing a significant privacy and security risk.
Vulnerability
This is a missing authentication for a critical function vulnerability (CWE-306). Remote, unauthenticated attackers can retrieve sensitive video imagery by directly querying unprotected endpoints such as middleImage.jpg and rightimage.jpg.
Business impact
The exposure of live video feeds from physical security sensors can lead to unauthorized surveillance of sensitive areas, including retail stores, banks, and transportation terminals. This unauthorized access compromises privacy, facilitates physical security reconnaissance, and presents a severe risk of reputational damage and regulatory non-compliance. Given the CVSS score of 7.5, this high-severity flaw requires immediate attention to prevent unauthorized data exfiltration.
Remediation
Immediate Action: Update the firmware and associated software components of the FLIR Brickstream 3D+ sensor to the latest available version provided by the manufacturer.
Proactive Monitoring: Inspect network traffic logs for unauthorized GET requests targeting image endpoints on these devices and monitor for unusual spikes in bandwidth consumption.
Compensating Controls: Isolate the affected devices on a restricted management VLAN and implement strict firewall rules to block external access to the device management interface.
Exploitation status
Public Exploit Available: Yes, a functional proof-of-concept script is available via the Exploit Database (EDB-ID: 45607).
Analyst recommendation
The ability for an unauthenticated user to access live video streams constitutes a major security failure that must be addressed immediately. Organizations currently deploying FLIR Brickstream 3D+ sensors should verify their firmware versions and apply all available security updates. Until patches are verified and applied, restricted network access is the most effective method to mitigate the risk of unauthorized stream exposure.
More FLIR Systems CVEs
Sources
Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.
- ExploitDB-45607 Exploit / PoC
- FLIR Brickstream Product Homepage
- Zero Science Lab Disclosure (ZSL-2018-5496) Third-party advisory