CVE-2023-46295: Teledyne Flir m300
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
An issue was discovered in Teledyne FLIR M300 2.00-19. Unauthenticated remote code execution can occur in the web server. An attacker can exploit this by sending a POST request to the vulnerable PHP page. An attacker can elevate to root permissions with Sudo.
Affected products
- Teledyne Flir m300: from 2.00-19, before 2.00-38 (fixed in 2.00-38)
Published 2024-05-01. Last modified 2026-06-17.