// For flags

CVE-2022-37061

FLIR AX8 1.46.16 Traversal / Access Control / Command Injection / XSS

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

8
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php endpoint. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the root privileges.

Todas las cámaras térmicas FLIR AX8 versiones hasta 1.46.16, son vulnerables a una Inyección de Comandos Remotos. Esto puede ser explotado para inyectar y ejecutar comandos shell arbitrarios como usuario root mediante el parámetro id HTTP POST en el endpoint res.php. Una explotación con exitoso podría permitir al atacante ejecutar comandos arbitrarios en el sistema operativo subyacente con los privilegios de root.

FLIR AX8 versions 1.46.16 and below suffer from command injection, directory traversal, improper access control, and cross site scripting vulnerabilities.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-08-01 CVE Reserved
  • 2022-08-18 CVE Published
  • 2022-08-19 First Exploit
  • 2024-08-03 CVE Updated
  • 2025-02-13 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Flir
Search vendor "Flir"
Flir Ax8 Firmware
Search vendor "Flir" for product "Flir Ax8 Firmware"
<= 1.46.16
Search vendor "Flir" for product "Flir Ax8 Firmware" and version " <= 1.46.16"
-
Affected
in Flir
Search vendor "Flir"
Flir Ax8
Search vendor "Flir" for product "Flir Ax8"
--
Safe