ID

VAR-201810-1642


CVE

CVE-2018-25138


TITLE

FLIR Systems FLIR AX8 Thermal Camera 1.32.16 Hard-coded Credentials Shell Access

Trust: 0.1

sources: ZSL: ZSL-2018-5494

DESCRIPTION

FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. Attackers can exploit these persistent credentials to gain unauthorized shell access and login to multiple camera interfaces using predefined username and password combinations. Thermal Imaging Camera For Continuous Condition and Safety Monitoring FLIR AX8 is a thermal sensor with imaging capabilities. Combining thermal and visual cameras in a small, affordable package, the AX8 provides continuous temperature monitoring and alarming capabilities to protec critical electrical and mechanical equipment. The AX8 helps you guard against unplanned outages, service interruptions, and equipment failure.<br/><br/> The FLIR AX series camera/sensor also has built-in support to connect to industrial control equipment such as programmable logic controllers (PLCs), and allows the sharing of analysis and alarm results and simple control using the Ethernet/IP and Modbus TCP field bus protocols. Compact and easy to install, the AX8 provides continuous monitoring of electrical cabinets, process and manufacturing areas, data centers, energy generation and distribution, transportation and mass transit, storage facilities and refrigeration warehouses.The devices utilizes hard-coded and credentials within its Linux distributionimage. Attacker could exploit thisvulnerability by logging in using the default credentials for the web panel or gainshell access.Tested on: GNU/Linux 3.0.35-flir+gfd883a0 (armv7l)lighttpd/1.4.33PHP/5.4.14

Trust: 0.99

sources: NVD: CVE-2018-25138 // ZSL: ZSL-2018-5494

AFFECTED PRODUCTS

vendor:flirmodel:ax8scope:eqversion:1.32.16

Trust: 1.0

vendor:flirmodel:ax8scope:eqversion:1.17.13

Trust: 1.0

vendor:flirmodel:systems flir ax8 thermal camerascope:eqversion:1.17.13

Trust: 0.1

vendor:flirmodel:systems flir ax8 thermal camerascope:eqversion:os: neco_v1.8-0-g7ffe5b3

Trust: 0.1

vendor:flirmodel:systems flir ax8 thermal camerascope:eqversion:hardware: flir systems neco board

Trust: 0.1

sources: ZSL: ZSL-2018-5494 // NVD: CVE-2018-25138

CVSS

SEVERITY

CVSSV2

CVSSV3

disclosure@vulncheck.com: CVE-2018-25138
value: CRITICAL

Trust: 1.0

nvd@nist.gov: CVE-2018-25138
value: CRITICAL

Trust: 1.0

ZSL: ZSL-2018-5494
value: (5/5)

Trust: 0.1

disclosure@vulncheck.com: CVE-2018-25138
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 2.0

sources: ZSL: ZSL-2018-5494 // NVD: CVE-2018-25138 // NVD: CVE-2018-25138

PROBLEMTYPE DATA

problemtype:CWE-798

Trust: 1.0

sources: NVD: CVE-2018-25138

TYPE

Local/Remote,System Access, DoS

Trust: 0.1

sources: ZSL: ZSL-2018-5494

EXPLOIT AVAILABILITY

sources: ZSL: ZSL-2018-5494

EXTERNAL IDS

db:EXPLOIT-DBid:45629

Trust: 1.1

db:ZSLid:ZSL-2018-5494

Trust: 1.1

db:NVDid:CVE-2018-25138

Trust: 1.0

db:PACKETSTORMid:149800

Trust: 0.1

sources: ZSL: ZSL-2018-5494 // NVD: CVE-2018-25138

REFERENCES

url:https://www.exploit-db.com/exploits/45629

Trust: 1.0

url:https://www.flir.com

Trust: 1.0

url:https://www.zeroscience.mk/en/vulnerabilities/zsl-2018-5494.php

Trust: 1.0

url:https://www.flir.com/security/best-practices-for-cybersecurity/

Trust: 0.1

url:https://www.flir.com/globalassets/security/flir-pro-security-cyber-hardening-guide.pdf

Trust: 0.1

url:https://www.flir.com/globalassets/security/cybersecurity-bulletin-10-12-18.pdf

Trust: 0.1

url:https://packetstormsecurity.com/files/149800

Trust: 0.1

url:https://www.exploit-db.com/exploits/45629/

Trust: 0.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/151332

Trust: 0.1

sources: ZSL: ZSL-2018-5494 // NVD: CVE-2018-25138

CREDITS

Vulnerability discovered by Gjoko Krstic

Trust: 0.1

sources: ZSL: ZSL-2018-5494

SOURCES

db:ZSLid:ZSL-2018-5494
db:NVDid:CVE-2018-25138

LAST UPDATE DATE

2026-01-15T23:36:18.249000+00:00


SOURCES UPDATE DATE

db:ZSLid:ZSL-2018-5494date:2018-10-18T00:00:00
db:NVDid:CVE-2018-25138date:2026-01-05T14:15:50.533

SOURCES RELEASE DATE

db:ZSLid:ZSL-2018-5494date:2018-10-14T00:00:00
db:NVDid:CVE-2018-25138date:2025-12-24T20:15:47.807