Critical severity9.8NVD Advisory· Published Dec 24, 2025· Updated Jun 17, 2026
CVE-2018-25138
CVE-2018-25138
Description
FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. Attackers can exploit these persistent credentials to gain unauthorized shell access and login to multiple camera interfaces using predefined username and password combinations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:o:flir:flir_ax8_firmware:1.17.13:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:flir:flir_ax8_firmware:1.17.13:*:*:*:*:*:*:*
- cpe:2.3:o:flir:flir_ax8_firmware:1.32.16:*:*:*:*:*:*:*
1.32.16+ 1 more
- (no CPE)range: 1.32.16
- (no CPE)range: 1.32.16
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/45629nvdExploitThird Party AdvisoryVDB Entry
- www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5494.phpnvdExploitThird Party Advisory
- www.flir.comnvdProduct
News mentions
0No linked articles in our index yet.