---
id: CVE-2026-14983
title: >-
  Missing authentication in the web interface in Teledyne FLIR Aware2 versions
  through 6.9.0.2 allows remote unauthenticated attackers to achieve denial of
  service against Teledyne FLIR PackBot robots running this software via misuse
  of th…
summary: >-
  Missing authentication in the web interface in Teledyne FLIR Aware2 versions
  through 6.9.0.2 allows remote unauthenticated attackers to achieve denial of
  service against Teledyne FLIR PackBot robots running this software via misuse
  of th…
severity: high
cvss: 7.1
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-306
vendor: Teledyne FLIR
product: Aware2
affected:
  - Aware2 <= 6.9.0.2
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T21:17:19.957'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14983'
references:
  - url: >-
      https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0027.md
    label: mandiant-cve@google.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-01T20:13:40.342217Z'
cvssSource: cna
ingestedAt: '2026-10-01T21:00:32.265Z'
---

## Overview

Missing authentication in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to achieve denial of service against Teledyne FLIR PackBot robots running this software via misuse of the reboot endpoint.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
