CVE-2026-55393
Received Received - Intake

Path Traversal Vulnerability in Teledyne FLIR Aware2

Vulnerability report for CVE-2026-55393, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Mandiant Inc.

Description

Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot and FirstLook robots running this software via path traversal.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
teledyne_flir aware2 to 6.9.0.2 (inc)
teledyne_flir packbot to 6.9.0.2 (inc)
teledyne_flir firstlook to 1.7.9 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves unvalidated pathnames in the web interface of Teledyne FLIR Aware2 software. It affects versions through 6.9.0.2 for PackBot and 1.7.9 for FirstLook. Remote unauthenticated attackers can exploit path traversal to read configuration and security parameters on Teledyne FLIR PackBot and FirstLook robots running this software.

Detection Guidance

This vulnerability involves path traversal in Teledyne FLIR Aware2 web interfaces. To detect it, check for unvalidated pathname handling in web requests to PackBot or FirstLook devices. Inspect HTTP requests for sequences like ../ or encoded variations to identify potential exploitation attempts.

Impact Analysis

An attacker could access sensitive configuration and security settings on robots running vulnerable software. This may allow unauthorized control or monitoring of the robots, potentially leading to operational disruptions or data breaches.

Compliance Impact

This vulnerability allows remote unauthenticated attackers to read configuration and security parameters via path traversal, which could expose sensitive data. This may violate compliance requirements for data protection standards like GDPR or HIPAA if such data includes personal or health information.

Mitigation Strategies

Update Teledyne FLIR Aware2 to versions beyond 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) to address the path traversal vulnerability. Ensure the web interface is not exposed to untrusted networks and restrict access to authorized users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55393. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart