Description
FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to bypass authentication and authorization controls. Attackers can directly modify device configurations, access system information, and potentially initiate denial of service by sending crafted WebSocket messages without authentication.
Problem types
Missing Authentication for Critical Function
Product status
E1.00.09
V1.02.P01
V1.05.P01
V1.04.P02
V1.04
V1.01.P02
V1.05.P03
V1.06
V1.02.P02
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5490.php
www.exploit-db.com/exploits/45539 (ExploitDB-45539)
www.flir.com (FLIR Systems Official Website)
www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5490.php (Zero Science Lab Disclosure (ZSL-2018-5490))
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.