S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jun 2, 2025

CVE-2022-37061 Scanner

CVE-2022-37061 Scanner - Remote Code Execution (RCE) vulnerability in FLIR AX8

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.3k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-37061
9.8
CVSS

All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php endpoint. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the root privileges. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

FLIR AX8 is a compact thermal imaging camera used primarily for condition monitoring, early fire detection, and process control in various industries. It is often employed in manufacturing, electrical utilities, data centers, and other facilities to ensure continuous, real-time monitoring of critical assets. The device functions autonomously or integrated within larger systems, delivering vital temperature data to operators. Given its industrial applications, the FLIR AX8 is an essential tool in monitoring thermal performance and preventing system failures. By capturing thermal images and providing analytics, it helps in identifying potential issues in an infrastructure. Its integration into security systems stems from its precision in detecting temperature anomalies.

Remote Code Execution (RCE) is a type of vulnerability that allows an attacker to execute arbitrary code on a remote machine over the network. This specific vulnerability is found in FLIR AX8 version 1.46.16 and below. RCE vulnerabilities are especially dangerous as they enable attackers to perform numerous actions ranging from stealing data to taking full control of the affected device. Due to improper input validation in the 'id' parameter, the FLIR AX8 is susceptible to such attacks. Exploiting this vulnerability could allow unauthorized users to run commands on the device's operating system. RCE vulnerabilities highlight the importance of secure coding practices and input sanitation.

The FLIR AX8 vulnerability stems from insufficient input validation in the device's alarm functionality, specifically within the 'id' parameter. Attackers can inject arbitrary operating system commands that the device then executes with potentially high privileges. During exploitation, user-supplied data bypasses sanitation checks, facilitating malicious command execution. This issue highlights the criticality of validating and sanitizing user inputs to prevent arbitrary command injection. The potential for exploitation via the alarm function in FLIR AX8 makes it an appealing target for attackers. This vulnerability affects systems operating on network protocols capable of accepting crafted payload requests.

The exploitation of the RCE vulnerability in FLIR AX8 could have severe consequences. An attacker may gain unauthorized access to the device, compromising its intended functionalities. Consequently, this could lead to the failure of critical systems relying on temperature data for automated decisions, potentially causing significant industrial disruptions. In more severe cases, misuse could result in the unauthorized control and monitoring of thermal data, risking confidentiality of sensitive information. The ability to execute commands remotely can lead to larger security incidents like data breach or lateral movement within a network. Such vulnerabilities highlight the critical need for regular security assessments and patch management.

REFERENCES

Solution Advice
  • Upgrade to the latest version of FLIR AX8 that addresses this vulnerability.
  • Implement robust input validation and sanitization for all user-supplied data within the system.
  • Conduct regular security assessments to identify and remediate potential vulnerabilities promptly.
  • Configure network controls to restrict unauthorized access to FLIR AX8 devices.
  • Ensure comprehensive logging and monitoring to detect and respond to any unusual activities quickly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-37061 Scanner - Remote Code Execution (RCE) vulnerability in FLIR AX8 | S4E