Information Disclosure in FLIR Thermal Camera Products
CVE-2017-20212
Key Information:
- Vendor
Flir Systems, Inc.
- Vendor
- CVE Published:
- 7 January 2026
Badges
What is CVE-2017-20212?
The firmware of FLIR Thermal Camera F/FC/PT/D version 8.0.0.64 is susceptible to an information disclosure vulnerability. This security flaw enables unauthenticated attackers to exploit the '/var/www/data/controllers/api/xml.php' readFile() function, allowing them to read arbitrary files from the local system. The flaw arises from unverified input parameters, providing a vector for unauthorized access to sensitive data. Proper security measures and timely updates are crucial to mitigate this risk.
Affected Version(s)
FLIR Thermal Camera F/FC/PT/D 8.0.0.64
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
