Access Control Flaw in Teledyne FLIR Robots by Teledyne
CVE-2026-55395

9.4CRITICAL

Key Information:

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-55395?

Teledyne FLIR Aware2 contains a significant security vulnerability that allows remote unauthenticated attackers to gain unauthorized access and reconfigure specific robotic models, namely the PackBot and FirstLook. This is due to hardcoded passwords being accessible through the firmware or associated documentation. The flaw raises serious concerns regarding the security and integrity of the affected robots, highlighting the need for improved password management and device security protocols.

Affected Version(s)

Aware2 0 <= 6.9.0.2

Aware2 0 <= 1.7.9

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.