OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-55393

CRITICAL · CVSS 10 EPSS 0.43% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Teledyne FLIR Aware2 versions up to 6.9.0.2 for PackBot and 1.7.9 for FirstLook are vulnerable due to unvalidated pathnames in their web interface, allowing remote unauthenticated attackers to exploit path traversal vulnerabilities. This critical flaw enables attackers to access sensitive configuration and security parameters of the affected robotic systems. Organizations utilizing these robots should prioritize immediate remediation to mitigate the risk of unauthorized access and potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55393
Severity
CRITICAL
CVSS
10
EPSS
0.43%

Original NVD Description

Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot and FirstLook robots running this software via path traversal.