CVE-2018-25137: Flir Systems, Inc Flir Brickstream 3d+
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability in the ExportConfig REST API that allows attackers to download sensitive configuration files. Attackers can exploit the getConfigExportFile.cgi endpoint to retrieve system configurations, potentially enabling authentication bypass and privilege escalation.
Affected products
- Flir Systems, Inc Flir Brickstream 3d+: version 2.1.742.1842 only
Published 2025-12-24. Last modified 2026-06-17.