CVE-2026-55395: Teledyne Flir AWARE2

Critical severity, CVSS 9.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne FLIR PackBot and FirstLook robots running this software via reading the passwords from the firmware or documentation.

Affected products

  • Teledyne Flir AWARE2: up to and including 6.9.0.2; up to and including 1.7.9

Published 2026-10-01. Last modified 2026-10-02.