CVE-2018-25141: Flir Thermal Traffic Cameras

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly retrieve video streams by accessing specific endpoints like /live.mjpeg, /snapshot.jpg, and RTSP streaming URLs without authentication.

Affected products

  • Flir Flir Thermal Traffic Cameras: version 1.01-0bb5b27 only

Published 2025-12-24. Last modified 2026-06-17.