CVE-2018-25138

7.5

FLIR Systems · AX8 Thermal Camera

The FLIR AX8 Thermal Camera contains hard-coded SSH and web panel credentials that cannot be modified, allowing unauthorized access to the device shell and management interfaces.

Executive summary

The FLIR AX8 Thermal Camera is vulnerable to unauthorized access due to hard-coded administrative credentials, posing a critical risk to physical security monitoring infrastructure.

Vulnerability

This vulnerability involves the use of hard-coded credentials (CWE-798) for both SSH access and web management panels. An unauthenticated attacker can leverage these known credentials to gain full shell access or administrative control over the camera.

Business impact

Successful exploitation allows an attacker to gain complete control over the thermal camera, potentially leading to the compromise of sensitive surveillance data or the integration of the device into a botnet. Given the CVSS score of 7.5, this high-severity vulnerability represents a significant risk to operational security, as cameras are often deployed in critical infrastructure environments where their compromise could facilitate broader network lateral movement.

Remediation

Immediate Action: Since a formal vendor patch is not confirmed, isolate affected cameras from the public internet immediately and restrict access to management interfaces to trusted internal networks only.

Proactive Monitoring: Monitor network traffic for unauthorized SSH connections originating from the camera or unusual login attempts to the web management interface.

Compensating Controls: Deploy a Web Application Firewall or network-based access control list to block unauthorized access to the camera management ports and disable SSH if it is not required for daily operations.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the Exploit-DB entry 45629.

Analyst recommendation

The presence of hard-coded credentials in security-critical hardware like thermal cameras presents a severe risk that cannot be easily mitigated by software updates alone. Administrators must prioritize network segmentation to ensure these devices are not reachable by unauthorized parties, as total device compromise is achievable by any actor with network access.

More FLIR Systems CVEs

Sources

Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.