← All Advisories

CVE-2026-55395

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-55395

Key Details

CVECVE-2026-55395
CVSS Score / Version9.4 (Critical) / CVSS v4.0
Updated2026-10-02
Affected productsTeledyne FLIR Aware2
Classified asCWE-798 (Use of Hard-coded Credentials)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Teledyne FLIRAware2
SubsystemsGeneral OT
SectorsMultiple

What to Know

Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne FLIR PackBot and FirstLook robots running this software via reading the passwords from the firmware or documentation.

What to Do

Monitor Teledyne FLIR's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-55395
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-55395