Command Injection Vulnerability in Teledyne FLIR FB-Series O and FH-Series ID
CVE-2025-7578
What is CVE-2025-7578?
A command injection vulnerability exists in Teledyne FLIR's FB-Series O and FH-Series ID products due to improper handling of the command argument in the sendCommand function within runcmd.sh. This flaw allows remote attackers to execute arbitrary commands, leveraging this function as an attack vector. Although currently mitigated by server CGI configuration issues, the vulnerability remains a significant threat, likened to a 'time bomb' that could be exploited if the misconfiguration is addressed. Attempts to notify the vendor of this vulnerability received no response.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FLIR FB-Series O 1.3.2.16
FLIR FH-Series ID 1.3.2.16
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
