CVE-2018-25137

FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability in the ExportConfig REST API that allows attackers to download sensitive configuration files. Attackers can exploit the getConfigExportFile.cgi endpoint to retrieve system configurations, potentially enabling authentication bypass and privilege escalation.
Configurations

No configuration.

History

24 Dec 2025, 21:15

Type Values Removed Values Added
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5495.php - () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5495.php -

24 Dec 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-24 20:15

Updated : 2025-12-29 15:58


NVD link : CVE-2018-25137

Mitre link : CVE-2018-25137

CVE.ORG link : CVE-2018-25137


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function