CVE-2026-55396
Received Received - Intake

Cleartext Transmission Flaw in Teledyne FLIR Aware2 Affects Robot Control

Vulnerability report for CVE-2026-55396, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Mandiant Inc.

Description

Cleartext transmission without a cryptographic integrity check in operator control unit to robot UDP traffic in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows adjacent unauthenticated attackers to intercept, hijack, or modify control traffic against Teledyne FLIR PackBot and FirstLook robots running this software via sniffing or hijacking network traffic.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
teledyne_flir aware2 to 6.9.0.2 (inc)
teledyne_flir packbot to 6.9.0.2 (inc)
teledyne_flir firstlook to 1.7.9 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves cleartext transmission of UDP traffic between operator control units and robots in Teledyne FLIR Aware2 software. It lacks cryptographic integrity checks, allowing adjacent unauthenticated attackers to intercept, hijack, or modify control traffic for PackBot and FirstLook robots running affected versions.

Detection Guidance

Detecting this vulnerability requires monitoring UDP traffic between the operator control unit and robots for cleartext transmission without cryptographic integrity checks. Use network sniffing tools like Wireshark or tcpdump to capture UDP packets and inspect for unencrypted control traffic. Look for PackBot or FirstLook robot communication patterns on standard UDP ports.

Impact Analysis

An attacker within network range could take control of robots, alter commands, or intercept sensitive data. This could lead to unauthorized access, operational disruptions, or physical harm depending on the robot's use case.

Compliance Impact

This vulnerability may violate data protection requirements under GDPR and HIPAA due to lack of encryption and integrity checks for sensitive control traffic. Non-compliance could result in legal penalties or data breaches.

Mitigation Strategies

Immediately isolate affected robots and operator control units on a dedicated, isolated network segment. Disable all external network access to these systems until patches are applied. Contact Teledyne FLIR support for updated software versions that implement cryptographic integrity checks for UDP traffic.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55396. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart