CVE-2017-20213
Severity CVSS v4.0:
HIGH
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
08/01/2026
Last modified:
08/01/2026
Description
FLIR Thermal Camera F/FC/PT/D Stream firmware version 8.0.0.64 contains an unauthenticated vulnerability that allows remote attackers to access live camera streams without credentials. Attackers can exploit the vulnerability to view unauthorized thermal camera video feeds across multiple camera series without requiring any authentication.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://cxsecurity.com/issue/WLB-2017090204
- https://packetstormsecurity.com/files/144323
- https://web.archive.org/web/20171011125811/https://www.flir.com/security/blog/details/?ID=87043
- https://www.exploit-db.com/exploits/42789/
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5435.php
- https://cxsecurity.com/issue/WLB-2017090204
- https://www.exploit-db.com/exploits/42789/
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5435.php



