CVE-2025-5695 | Teledyne FLIR AX8 up to 1.46.16 Backend subscriptions.php command injection (EUVD-2025-17027)
A vulnerability was found in Teledyne FLIR AX8 up to 1.46.16 and classified as critical. This impacts the function subscribe_to_spot/subscribe_to_delta/subscribe_to_alarm of the file /usr/www/application/models/subscriptions.php of the component Backend. Such manipulation leads to command injection.
This vulnerability is referenced as CVE-2025-5695. It is possible to launch the attack remotely. Furthermore, an exploit is available.
It is suggested to upgrade the affected component.
The vendor points out: "FLIR AX8 internal web site has been refactored to be able to handle the reported vulnerabilities."