CVE-2018-25140

7.5

FLIR Systems, Inc. · Thermal Traffic Cameras (ITS models)

FLIR thermal traffic cameras contain an unauthenticated WebSocket vulnerability allowing attackers to bypass authentication, modify device configurations, and initiate denial of service attacks.

Executive summary

An unauthenticated vulnerability in the WebSocket implementation of FLIR thermal traffic cameras allows remote attackers to fully compromise device integrity and availability.

Vulnerability

This is a missing authentication for critical function flaw (CWE-306) within the WebSocket communication interface. An unauthenticated attacker can send crafted messages to the device, facilitating unauthorized configuration changes, information disclosure, and system reboots.

Business impact

Successful exploitation poses a severe risk to infrastructure operations, as traffic cameras are critical for monitoring and safety systems. An attacker could remotely manipulate camera settings, disable monitoring capabilities, or cause persistent denial of service, leading to operational downtime and potential safety hazards. The CVSS score of 7.5 reflects the high impact on confidentiality, integrity, and availability, even without requiring user interaction or prior authentication.

Remediation

Immediate Action: Update affected camera firmware to the patched versions identified by the vendor, such as E1.06.03 for ThermiCam or TrafiSense models, to close the authentication bypass.

Proactive Monitoring: Monitor network traffic for unusual WebSocket upgrade requests originating from untrusted sources, particularly targeting the specific communication port 13042.

Compensating Controls: Implement strict network segmentation to isolate traffic cameras from public-facing networks and deploy a Web Application Firewall or network-level access control list to restrict access to the device management interface.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exploit is available via ExploitDB (EDB-ID 45539).

Analyst recommendation

Given the potential for complete device manipulation and the availability of public exploit code, organizations must prioritize patching these devices immediately. If a firmware update cannot be applied promptly, the affected cameras should be removed from internet-facing networks to prevent unauthorized access and potential disruption of critical traffic monitoring services.

More FLIR Systems, Inc. CVEs

Sources

Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.