CVE-2026-55394
Received Received - Intake

Unencrypted Traffic in Teledyne FLIR Aware2 Network

Vulnerability report for CVE-2026-55394, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Mandiant Inc.

Description

Unencrypted traffic in the 802.11 network of Teledyne FLIR Aware2 versions through 6.9.0.2 allows adjacent unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FLIR PackBot robots running this software via sniffing or hijacking network traffic.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
teledyne_flir aware2 to 6.9.0.2 (inc)
teledyne_flir packbot *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves unencrypted network traffic in Teledyne FLIR Aware2 versions up to 6.9.0.2. Attackers within range can intercept, hijack, or modify session traffic for Teledyne FLIR PackBot robots using this software by sniffing or hijacking the network traffic.

Detection Guidance

Detect unencrypted 802.11 traffic on your network by monitoring Wi-Fi traffic for cleartext sessions involving Teledyne FLIR Aware2 or PackBot devices. Use tools like Wireshark or tcpdump to capture and analyze network traffic for unencrypted protocols or sessions.

Impact Analysis

Unauthenticated attackers nearby could gain unauthorized access to robot sessions, potentially taking control or altering operations. This could lead to data breaches, operational disruptions, or safety risks depending on the robot's use case.

Compliance Impact

This vulnerability involves unencrypted network traffic in Teledyne FLIR Aware2 and PackBot systems, which could allow interception or modification of session data. Such exposure risks non-compliance with GDPR due to potential unauthorized access to personal data and HIPAA due to lack of encryption for sensitive information during transmission.

Mitigation Strategies

Immediately update Teledyne FLIR Aware2 to the latest version beyond 6.9.0.2. Ensure all network traffic for PackBot robots is encrypted by configuring secure protocols and disabling unencrypted communication channels.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55394. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart