OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-55396

HIGH · CVSS 8.5 EPSS 0.11% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Teledyne FLIR Aware2 versions up to 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) are vulnerable due to cleartext transmission of UDP traffic without cryptographic integrity checks, enabling adjacent unauthenticated attackers to intercept, hijack, or modify control commands. This vulnerability poses a significant risk to the operational integrity of robotic systems, potentially leading to unauthorized control or manipulation. Organizations utilizing these robotic systems should prioritize remediation to safeguard against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55396
Severity
HIGH
CVSS
8.5
EPSS
0.11%

Original NVD Description

Cleartext transmission without a cryptographic integrity check in operator control unit to robot UDP traffic in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows adjacent unauthenticated attackers to intercept, hijack, or modify control traffic against Teledyne FLIR PackBot and FirstLook robots running this software via sniffing or hijacking network traffic.