CVE-2018-25140: Flir Systems, Inc Thermal Traffic Cameras
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to bypass authentication and authorization controls. Attackers can directly modify device configurations, access system information, and potentially initiate denial of service by sending crafted WebSocket messages without authentication.
Affected products
- Flir Systems, Inc Thermal Traffic Cameras: version V1.01-0bb5b27 only; version E1.00.09 only; version V1.02.P01 only; version V1.05.P01 only; version V1.04.P02 only; version V1.04 only; …
Published 2025-12-24. Last modified 2026-06-17.