CVE-2026-55395 PUBLISHED

Hardcoded Passwords in Teledyne FLIR Robots running Aware2

Assigner: Mandiant
Reserved: 16.06.2026 Published: 01.10.2026 Updated: 01.10.2026

Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne FLIR PackBot and FirstLook robots running this software via reading the passwords from the firmware or documentation.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.4

Product Status

Vendor Teledyne FLIR
Product Aware2
Versions Default: unaffected
  • affected from 0 to 6.9.0.2 (incl.)
  • affected from 0 to 1.7.9 (incl.)

References

Problem Types

  • CWE-798: Use of Hard-coded Credentials CWE

Impacts

  • CAPEC-191: Read Sensitive Constants Within an Executable