CVE-2018-25140
HIGHFLIR thermal traffic cameras - SSRF
Title source: llmDescription
FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to bypass authentication and authorization controls. Attackers can directly modify device configurations, access system information, and potentially initiate denial of service by sending crafted WebSocket messages without authentication.
Exploits (1)
exploitdb
WORKING POC
by LiquidWorm · pythonwebappshardware
https://www.exploit-db.com/exploits/45539
Scores
CVSS v3
7.5
EPSS
0.0012
EPSS Percentile
30.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-306
Status
draft
Timeline
Published
Dec 24, 2025
Tracked Since
Feb 18, 2026