Status: UPDATED
| Advisory ID: CVE-2026-55393
Key Details
| CVE | CVE-2026-55393 |
| CVSS Score / Version | 10.0 (Critical) / CVSS v4.0 |
| Updated | 2026-10-02 |
| Affected products | Teledyne FLIR Aware2 |
| Classified as | CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot and FirstLook robots running this software via path traversal.
What to Do
Monitor Teledyne FLIR's web page for any future patch releases.
References