CVE-2017-20212
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
08/01/2026
Last modified:
08/01/2026
Description
FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains an information disclosure vulnerability that allows unauthenticated attackers to read arbitrary files through unverified input parameters. Attackers can exploit the /var/www/data/controllers/api/xml.php readFile() function to access local system files without authentication.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
6.20
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://cxsecurity.com/issue/WLB-2017090202
- https://packetstormsecurity.com/files/144322
- https://web.archive.org/web/20171011125811/https://www.flir.com/security/blog/details/?ID=87043
- https://www.exploit-db.com/exploits/42786/
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5434.php
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5434.php



