{"id":"CVE-2026-55393","title":"Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot an…","summary":"Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot an…","severity":"critical","cvss":10,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","cwe":["CWE-22"],"vendor":"Teledyne FLIR","product":"Aware2","affected":["Aware2 <= 6.9.0.2","Aware2 <= 1.7.9"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T21:17:21.540","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55393","references":[{"url":"https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0029.md","label":"mandiant-cve@google.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-10-01T20:28:46.870936Z"},"cvssSource":"cna","ingestedAt":"2026-10-01T21:00:32.269Z","slug":"CVE-2026-55393","body":"## Overview\n\nUnvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot and FirstLook robots running this software via path traversal.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":55,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}