CVE-2022-37061
CRITICAL EXPLOITED IN THE WILD NUCLEIFLIR AX8 Firmware <= 1.46.16 - Remote Command Injection via res.php id Parameter
Title source: llmExploitation Summary
CVE-2022-37061 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).
EIP tracks 2 public exploits from researchers including ub3rsick, Thomas Knudsen (https://www.linkedin.com/in/thomasjknudsen), Samy Younsi (https://www.linkedin.com/in/samy-younsi), h00die-gr3y, including a Metasploit module exploits/linux/http/flir_ax8_unauth_rce_cve_2022_37061.
A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit leverages an unauthenticated remote command injection vulnerability in FLIR AX8 devices (CVE-2022-37061) to execute a reverse shell. The payload is injected via the 'res.php' endpoint using a crafted POST request.
Description
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php endpoint. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the root privileges. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.
Exploits (2)
This exploit leverages an unauthenticated remote command injection vulnerability in FLIR AX8 devices (CVE-2022-37061) to execute a reverse shell. The payload is injected via the 'res.php' endpoint using a crafted POST request.
This Metasploit module exploits CVE-2022-37061, an unauthenticated remote command injection vulnerability in FLIR AX8 thermal sensor cameras. It injects commands via the 'id' parameter in the 'res.php' endpoint, allowing root-level execution.
Nuclei Templates (1)
title:"FLIR"
app="FLIR-AX8"
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H