CVE-2018-25139
7.5FLIR Systems, Inc. · AX8 Thermal Camera
The FLIR AX8 Thermal Camera contains an unauthenticated vulnerability that allows remote attackers to access and record live RTSP video streams without requiring valid credentials.
Executive summary
The FLIR AX8 Thermal Camera suffers from a critical authentication bypass vulnerability that permits unauthorized remote access to live video streams, posing a significant privacy and security risk.
Vulnerability
This is a missing authentication for critical function vulnerability (CWE-306) affecting the RTSP streaming service. An unauthenticated remote attacker can connect directly to the camera's video stream or manipulate its state via the device's web interface.
Business impact
The ability for unauthorized parties to view and record thermal camera footage can lead to the exposure of sensitive physical security environments, proprietary operational data, or private personnel movements. Given the CVSS score of 7.5, this high-severity vulnerability represents a substantial risk to facility security and operational confidentiality, as the attack requires no specialized access or authentication.
Remediation
Immediate Action: Ensure the device is isolated from public-facing networks and consult the vendor for available firmware updates that address unauthorized RTSP access.
Proactive Monitoring: Review network access logs for suspicious connections to the camera's IP address, particularly traffic directed at RTSP ports or the web-based management interface.
Compensating Controls: Implement strict network segmentation and place the camera behind a firewall that restricts access to trusted IP addresses only, effectively mitigating the risk of unauthorized external access.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the Exploit-DB entry 45606.
Analyst recommendation
Given the availability of public exploit code and the ease with which these devices can be monitored by unauthorized parties, immediate action is required. Organizations utilizing FLIR AX8 cameras must ensure these devices are not exposed to the public internet and should verify their firmware status with the vendor to apply any available security patches.
More FLIR Systems, Inc. CVEs
Sources
Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.
- ExploitDB-45606 Exploit / PoC
- FLIR Systems Official Product Homepage
- Zero Science Lab Disclosure (ZSL-2018-5492) Third-party advisory