๐Ÿ” CVE Alert

CVE-2018-25141

HIGH 7.5

FLIR Thermal Traffic Cameras V1.01-0bb5b27 Unauthenticated RTSP Stream Disclosure

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly retrieve video streams by accessing specific endpoints like /live.mjpeg, /snapshot.jpg, and RTSP streaming URLs without authentication.

CWE CWE-306
Vendor flir
Product flir thermal traffic cameras
Published Dec 24, 2025
Last Updated Mar 5, 2026
Stay Ahead of the Next One

Get instant alerts for flir flir thermal traffic cameras

Be the first to know when new high vulnerabilities affecting flir flir thermal traffic cameras are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

FLIR / FLIR Thermal Traffic Cameras
1.01-0bb5b27

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
exploit-db.com: https://www.exploit-db.com/exploits/45537 flir.com: https://www.flir.com zeroscience.mk: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5489.php

Credits

LiquidWorm as Gjoko Krstic of Zero Science Lab