---
id: CVE-2026-55395
title: >-
  Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions
  through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated
  attackers to access and reconfigure Teledyne FLIR PackBot and FirstLook robots
  runni…
summary: >-
  Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions
  through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated
  attackers to access and reconfigure Teledyne FLIR PackBot and FirstLook robots
  runni…
severity: critical
cvss: 9.4
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'
cwe:
  - CWE-798
vendor: Teledyne FLIR
product: Aware2
affected:
  - Aware2 <= 6.9.0.2
  - Aware2 <= 1.7.9
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T21:17:21.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55395'
references:
  - url: >-
      https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0031.md
    label: mandiant-cve@google.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-01T20:25:20.362662Z'
cvssSource: cna
ingestedAt: '2026-10-01T21:00:32.272Z'
---

## Overview

Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne FLIR PackBot and FirstLook robots running this software via reading the passwords from the firmware or documentation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
