CVE-2026-55393: Teledyne Flir AWARE2

Critical severity, CVSS 10.0. EPSS: 0.4% chance of exploitation in the next 30 days.

Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot and FirstLook robots running this software via path traversal.

Affected products

  • Teledyne Flir AWARE2: up to and including 6.9.0.2; up to and including 1.7.9

Published 2026-10-01. Last modified 2026-10-02.