CVE-2026-14983
Received Received - Intake

Authentication Bypass in Teledyne FLIR Aware2 Web Interface

Vulnerability report for CVE-2026-14983, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Mandiant Inc.

Description

Missing authentication in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to achieve denial of service against Teledyne FLIR PackBot robots running this software via misuse of the reboot endpoint.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
teledyne flir_aware2 to 6.9.0.2 (inc)
teledyne flir_packbot *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-14983 is a missing authentication vulnerability in the web interface of Teledyne FLIR Aware2 versions through 6.9.0.2. It allows remote unauthenticated attackers to cause denial of service against PackBot robots by exploiting the reboot endpoint without requiring any credentials.

Detection Guidance

To detect this vulnerability, monitor network traffic for unauthorized HTTP GET requests targeting the reboot endpoint of Teledyne FLIR Aware2 web interfaces. Check for repeated reboot commands or unusual system behavior like persistent reboot loops. Inspect logs for suspicious activity on ports typically used by the web interface.

Impact Analysis

This vulnerability enables attackers to force PackBot robots into a persistent reboot loop, rendering them inoperable during critical missions like explosive ordnance disposal or reconnaissance. Exploitation requires network access, which may be easier on older unencrypted networks but harder on modern encrypted deployments.

Compliance Impact

This vulnerability could impact compliance with standards requiring physical security and operational reliability of critical systems. For example, HIPAA requires safeguards for protected health information, and a non-functional robot could disrupt medical or emergency response operations. GDPR focuses on data protection, but this flaw risks operational disruption rather than direct data exposure.

Mitigation Strategies

Immediately restrict network access to the Teledyne FLIR Aware2 web interface. Apply the remediation guidance provided by Teledyne by September 30, 2026. Ensure all deployments use encrypted networks to prevent unauthorized access. Monitor systems for signs of exploitation and reboot loops.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14983. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart