OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-55395

CRITICAL · CVSS 9.4 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Teledyne FLIR Aware2 versions up to 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) contain hardcoded passwords in their access control mechanisms, enabling remote unauthenticated attackers to gain unauthorized access and reconfigure the robots. This vulnerability poses a critical risk, as it could lead to unauthorized manipulation of robotic systems in sensitive environments. Organizations using these specific robot models should prioritize immediate remediation to mitigate potential security breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55395
Severity
CRITICAL
CVSS
9.4
EPSS
0.18%

Original NVD Description

Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne FLIR PackBot and FirstLook robots running this software via reading the passwords from the firmware or documentation.