CVE-2022-37061

CRITICAL EXPLOITED IN THE WILD NUCLEI

FLIR AX8 Firmware <= 1.46.16 - Remote Command Injection via res.php id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-37061 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 2 public exploits from researchers including ub3rsick, Thomas Knudsen (https://www.linkedin.com/in/thomasjknudsen), Samy Younsi (https://www.linkedin.com/in/samy-younsi), h00die-gr3y, including a Metasploit module exploits/linux/http/flir_ax8_unauth_rce_cve_2022_37061. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit leverages an unauthenticated remote command injection vulnerability in FLIR AX8 devices (CVE-2022-37061) to execute a reverse shell. The payload is injected via the 'res.php' endpoint using a crafted POST request.

Description

All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php endpoint. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the root privileges. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.

Exploits (2)

exploitdb WORKING POC
by ub3rsick · pythonwebappshardware
https://www.exploit-db.com/exploits/52240

This exploit leverages an unauthenticated remote command injection vulnerability in FLIR AX8 devices (CVE-2022-37061) to execute a reverse shell. The payload is injected via the 'res.php' endpoint using a crafted POST request.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: FLIR AX8 version 1.46.16 and under
No auth needed
Prerequisites: Network access to the target device · Target device must be running a vulnerable version of FLIR AX8
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Thomas Knudsen (https://www.linkedin.com/in/thomasjknudsen), Samy Younsi (https://www.linkedin.com/in/samy-younsi), h00die-gr3y · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/flir_ax8_unauth_rce_cve_2022_37061.rb

This Metasploit module exploits CVE-2022-37061, an unauthenticated remote command injection vulnerability in FLIR AX8 thermal sensor cameras. It injects commands via the 'id' parameter in the 'res.php' endpoint, allowing root-level execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: FLIR AX8 thermal sensor cameras (versions up to and including 1.46.16)
No auth needed
Prerequisites: Network access to the target device · Target device running vulnerable FLIR AX8 firmware
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

FLIR AX8 1.46.16 - Remote Command Injection
CRITICALVERIFIEDby ritikchaddha
Shodan: title:"FLIR"
FOFA: app="FLIR-AX8"

Scores

CVSS v3 9.8
EPSS 0.9962
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2022-12-06
InTheWild.io 2022-12-21
CWE
CWE-78
Status published
Products (1)
flir/flir_ax8_firmware < 1.46.16
Published Aug 18, 2022
Tracked Since Feb 18, 2026