CVE-2022-37061
FLIR AX8 1.46.16 Traversal / Access Control / Command Injection / XSS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
8Exploited in Wild
-Decision
Descriptions
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php endpoint. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the root privileges.
Todas las cámaras térmicas FLIR AX8 versiones hasta 1.46.16, son vulnerables a una Inyección de Comandos Remotos. Esto puede ser explotado para inyectar y ejecutar comandos shell arbitrarios como usuario root mediante el parámetro id HTTP POST en el endpoint res.php. Una explotación con exitoso podría permitir al atacante ejecutar comandos arbitrarios en el sistema operativo subyacente con los privilegios de root.
FLIR AX8 versions 1.46.16 and below suffer from command injection, directory traversal, improper access control, and cross site scripting vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-08-01 CVE Reserved
- 2022-08-18 CVE Published
- 2022-08-19 First Exploit
- 2024-08-03 CVE Updated
- 2025-02-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
https://attackerkb.com/topics/UAZaDsQBfx/cve-2022-37061 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.flir.com/products/ax8-automation | 2022-12-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Flir Search vendor "Flir" | Flir Ax8 Firmware Search vendor "Flir" for product "Flir Ax8 Firmware" | <= 1.46.16 Search vendor "Flir" for product "Flir Ax8 Firmware" and version " <= 1.46.16" | - |
Affected
| in | Flir Search vendor "Flir" | Flir Ax8 Search vendor "Flir" for product "Flir Ax8" | - | - |
Safe
|