Sploitus

CVE-2018-25140

1 known exploit for CVE-2018-25140

FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to bypass authentication and authorization controls. Attackers can directly modify device configurations, access system information, and potentially initiate denial of service by sending crafted WebSocket messages without authentication.

CVSS 4.0
9.3 CRITICAL
CVSS 3.1
7.5 HIGH
EPSS
0.3% (23th percentile)
Weakness
CWE-306
NVD status
Deferred
Published
2025-12-24
CVE-2018-25140 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2018-25140

Proof-of-concept code and exploit modules indexed by Sploitus