Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-25140. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated information disclosure vulnerability in FLIR thermal traffic cameras via insecure WebSocket communication. It sends a crafted message to retrieve product information without authentication.
Description
FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to bypass authentication and authorization controls. Attackers can directly modify device configurations, access system information, and potentially initiate denial of service by sending crafted WebSocket messages without authentication.
Exploits (1)
This exploit demonstrates an unauthenticated information disclosure vulnerability in FLIR thermal traffic cameras via insecure WebSocket communication. It sends a crafted message to retrieve product information without authentication.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N