---
id: CVE-2018-25139
title: FLIR AX8 Thermal Camera 1.32.16 Unauthenticated RTSP Stream Disclosure
summary: >-
  FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that
  allows remote attackers to access live video streams without credentials.
  Attackers can directly connect to the RTSP stream using tools like VLC or
  FFmpeg to …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-306
vendor: 'FLIR Systems, Inc.'
product: FLIR AX8 Thermal Camera
affected:
  - flir_ax8_thermal_camera 1.32.16
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2025-12-24T20:12:45.552406Z'
exploitAvailable: true
published: '2025-12-24'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T19:19:02.555Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2018-25139'
references:
  - url: 'https://www.exploit-db.com/exploits/45606'
    label: ExploitDB-45606
  - url: 'https://www.flir.com'
    label: FLIR Systems Official Product Homepage
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5492.php'
    label: Zero Science Lab Disclosure (ZSL-2018-5492)
tags:
  - cve.org
  - exploit-available
epss: 0.00531
epssPercentile: 0.42819
ingestedAt: '2026-10-01T19:58:57.583Z'
---

## Overview

FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly connect to the RTSP stream using tools like VLC or FFmpeg to view and record thermal camera footage.

## Affected

- `flir_ax8_thermal_camera 1.32.16`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
