Vulnerability record · CVE-2022-37060 · published 18 August 2022
CVE-2022-37060: Flir ax8 firmware path traversal vulnerability
Flir · Flir Ax8 Firmware
FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains directory traversal characters to disclose the contents of files located outside of the server's restricted path. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.
Description
FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains directory traversal characters to disclose the contents of files located outside of the server's restricted path. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/168116/FLIR-AX8-1.46.16-Traversal-Access-Control-Command-Injection-XSS.html | ExploitThird Party AdvisoryVDB Entry |
| https://gist.github.com/Nwqda/9e16852ab7827dc62b8e44d6180a6899 | ExploitMitigationThird Party Advisory |
| https://www.flir.com/products/ax8-automation/ | ProductVendor Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5493.php | Third Party Advisory |
| http://packetstormsecurity.com/files/168116/FLIR-AX8-1.46.16-Traversal-Access-Control-Command-Injection-XSS.html | ExploitThird Party AdvisoryVDB Entry |
| https://gist.github.com/Nwqda/9e16852ab7827dc62b8e44d6180a6899 | ExploitMitigationThird Party Advisory |
| https://www.flir.com/products/ax8-automation/ | ProductVendor Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5493.php | Third Party Advisory |
Track CVE-2022-37060 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-37060), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.