CVE-2025-7577
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-07-14

Last updated on: 2026-04-29

Assigner: VulDB

Description
A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16. It has been classified as problematic. This affects an unknown part. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-14
Last Modified
2026-04-29
Generated
2026-05-27
AI Q&A
2025-07-14
EPSS Evaluated
2026-05-25
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
teledyne flir_fb-series_o 1.3.2.16
teledyne flir_fh-series_id 1.3.2.16
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-255
CWE-259 The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in Teledyne FLIR FB-Series O and FLIR FH-Series ID firmware version 1.3.2.16. It involves a hard-coded password for the system's root user, which is weak and easily guessable. This allows unauthorized remote attackers to gain root-level access without authentication by exploiting the embedded hard-coded credentials. [1, 2]


How can this vulnerability impact me? :

The vulnerability allows remote attackers to gain unauthorized root-level access to the affected devices without authentication. This compromises the confidentiality of the system and could lead to unauthorized control or data exposure. Although the attack complexity is high and exploitability is difficult, a public proof-of-concept exploit exists, increasing the risk. [1, 2]


How can this vulnerability be detected on my network or system? Can you suggest some commands?

Detection can focus on identifying the use of the hard-coded root password in FLIR FB-Series O and FH-Series ID devices running firmware 1.3.2.16. Since the vulnerability involves a known hard-coded password, network monitoring for unauthorized root access attempts or scanning for devices with this firmware version may help. However, no specific detection commands or tools are provided in the available resources. Monitoring for suspicious login attempts using the root account remotely could be useful. [1, 2]


What immediate steps should I take to mitigate this vulnerability?

Immediate mitigation steps include replacing the affected FLIR FB-Series O and FH-Series ID devices running firmware 1.3.2.16 with alternative products, as no vendor patch or countermeasures are available. Restricting network access to these devices and monitoring for unauthorized access attempts may reduce risk. Since the vendor has not responded and no fixes exist, removing or isolating the vulnerable devices is recommended. [2]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart