CVE-2026-55393 PUBLISHED

Local File Inclusion in Teledyne FLIR Robots running Aware2

Assigner: Mandiant
Reserved: 16.06.2026 Published: 01.10.2026 Updated: 01.10.2026

Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot and FirstLook robots running this software via path traversal.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 10

Product Status

Vendor Teledyne FLIR
Product Aware2
Versions Default: unaffected
  • affected from 0 to 6.9.0.2 (incl.)
  • affected from 0 to 1.7.9 (incl.)

References

Problem Types

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE

Impacts

  • CAPEC-497: File Discovery