---
id: CVE-2026-55393
title: >-
  Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions
  through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated
  attackers to read configuration and security parameters on Teledyne FLIR
  PackBot an…
summary: >-
  Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions
  through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated
  attackers to read configuration and security parameters on Teledyne FLIR
  PackBot an…
severity: critical
cvss: 10
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'
cwe:
  - CWE-22
vendor: Teledyne FLIR
product: Aware2
affected:
  - Aware2 <= 6.9.0.2
  - Aware2 <= 1.7.9
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T21:17:21.540'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55393'
references:
  - url: >-
      https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0029.md
    label: mandiant-cve@google.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-10-01T20:28:46.870936Z'
cvssSource: cna
ingestedAt: '2026-10-01T21:00:32.269Z'
---

## Overview

Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot and FirstLook robots running this software via path traversal.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
