vendor:
FLIR AX8 Thermal Camera
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Hard-Coded Credentials
798
CWE
Product Name: FLIR AX8 Thermal Camera
Affected Version From: Firmware: 1.32.16, 1.17.13, OS: neco_v1.8-0-g7ffe5b3
Affected Version To: Firmware: 1.32.16, 1.17.13, OS: neco_v1.8-0-g7ffe5b3
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: GNU/Linux 3.0.35-flir+gfd883a0 (armv7l), lighttpd/1.4.33, PHP/5.4.14
2018
FLIR AX8 Thermal Camera 1.32.16 – Hard-Coded Credentials
The devices utilizes hard-coded and credentials within its Linux distribution image. These sets of credentials (SSH) are never exposed to the end-user and cannot be changed through any normal operation of the camera. Attacker could exploit this vulnerability by logging in using the default credentials for the web panel or gain shell access.
Mitigation:
Change the default credentials and disable SSH access.