Cleartext Transmission Vulnerability in Teledyne FLIR Aware2 Products
CVE-2026-55396

8.5HIGH

Key Information:

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-55396?

A vulnerability exists in Teledyne FLIR's Aware2 software that permits cleartext transmission of control data for PackBot and FirstLook robots. This flaw allows nearby unauthenticated attackers to intercept and potentially manipulate the UDP traffic used by these devices. By exploiting the lack of a cryptographic integrity check, attackers can hijack or modify control commands, posing a significant risk to the operational integrity of these robotic systems.

Affected Version(s)

Aware2 0 <= 6.9.0.2

Aware2 0 <= 1.7.9

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.