CVE-2023-51126
Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 31.1%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 31.10% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- flir/flir ax8 firmware
- Source
- cve@mitre.org
References
- https://github.com/risuxx/CVE-2023-51126Third Party Advisory
- https://github.com/risuxx/CVE-2023-51126Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.