Unrestricted File Upload Vulnerability in FLIR AX8 by FLIR Systems
CVE-2025-6266
Key Information:
Badges
What is CVE-2025-6266?
A significant security issue has been identified in the FLIR AX8 device, specifically related to the /upload.php file. This vulnerability allows attackers to manipulate the 'File' parameter, resulting in an unrestricted file upload, which can be exploited remotely. As a result, unauthorized users may upload malicious files to the server, posing severe security risks. This vulnerability has been made public, and although the vendor was informed, there has been no response regarding this matter.
Affected Version(s)
AX8 1.0
AX8 1.1
AX8 1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved