CVE-2018-25139

FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly connect to the RTSP stream using tools like VLC or FFmpeg to view and record thermal camera footage.
References
Link Resource
https://www.exploit-db.com/exploits/45606 Exploit Third Party Advisory VDB Entry
https://www.flir.com Product
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5492.php Exploit Third Party Advisory
https://www.exploit-db.com/exploits/45606 Exploit Third Party Advisory VDB Entry
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5492.php Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:flir:flir_ax8_firmware:1.32.16:*:*:*:*:*:*:*
cpe:2.3:h:flir:flir_ax8:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:flir:flir_ax8_firmware:1.17.13:*:*:*:*:*:*:*
cpe:2.3:h:flir:flir_ax8:-:*:*:*:*:*:*:*

History

31 Dec 2025, 18:40

Type Values Removed Values Added
CPE cpe:2.3:o:flir:flir_ax8_firmware:1.32.16:*:*:*:*:*:*:*
cpe:2.3:o:flir:flir_ax8_firmware:1.17.13:*:*:*:*:*:*:*
cpe:2.3:h:flir:flir_ax8:-:*:*:*:*:*:*:*
First Time Flir flir Ax8 Firmware
Flir flir Ax8
Flir
References () https://www.exploit-db.com/exploits/45606 - () https://www.exploit-db.com/exploits/45606 - Exploit, Third Party Advisory, VDB Entry
References () https://www.flir.com - () https://www.flir.com - Product
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5492.php - () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5492.php - Exploit, Third Party Advisory

24 Dec 2025, 21:15

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/45606 - () https://www.exploit-db.com/exploits/45606 -
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5492.php - () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5492.php -

24 Dec 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-24 20:15

Updated : 2025-12-31 18:40


NVD link : CVE-2018-25139

Mitre link : CVE-2018-25139

CVE.ORG link : CVE-2018-25139


JSON object : View

Products Affected

flir

  • flir_ax8
  • flir_ax8_firmware
CWE
CWE-306

Missing Authentication for Critical Function