Status: UPDATED
| Advisory ID: CVE-2026-55395
Key Details
| CVE | CVE-2026-55395 |
| CVSS Score / Version | 9.4 (Critical) / CVSS v4.0 |
| Updated | 2026-10-02 |
| Affected products | Teledyne FLIR Aware2 |
| Classified as | CWE-798 (Use of Hard-coded Credentials) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne FLIR PackBot and FirstLook robots running this software via reading the passwords from the firmware or documentation.
What to Do
Monitor Teledyne FLIR's web page for any future patch releases.
References