CVE-2022-37061

CRITICAL ⚠ Exploit

All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root ...

Affects 2 products across 1 vendor.

BCS8.88
CVSS 3.19.8
EPSS99.6%
Percentile100th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-78: OS Command Injection

Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.

Related Attack Patterns (CAPEC)
CAPEC-43 Exploiting Multiple Input Interpretation Layers
via CWE-78
CAPEC-108 Command Line Execution through SQL Injection
via CWE-78
CAPEC-6 Argument Injection
via CWE-78
CAPEC-15 Command Delimiters
via CWE-78
CAPEC-88 OS Command Injection
via CWE-78

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

FLIR AX8 thermal sensor cameras up to version 1.46.16 are vulnerable to Remote Command Injection, allowing attackers to execute arbitrary shell commands as the root user.

BSID: BS-2022-GLOBAL-157213-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2022-37061?
FLIR AX8 thermal sensor cameras up to version 1.46.16 are vulnerable to Remote Command Injection, allowing attackers to execute arbitrary shell commands as the root user.
What is the CVSS score for CVE-2022-37061?
CVE-2022-37061 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 99.6%.
Is CVE-2022-37061 actively exploited?
Public exploit available for CVE-2022-37061. Exploitation risk elevated.
How do I remediate CVE-2022-37061?
Priority: IMMEDIATE. Advisory: https://www.flir.com/products/ax8-automation/ PSIRT: [email protected]
What systems are affected by CVE-2022-37061?
CVE-2022-37061 affects: Flir, Flir.
Vulnerability Details
CVE IDCVE-2022-37061
BSIDBS-2022-GLOBAL-157213-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2022-08-18
Last Modified2025-10-17
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php endpoint. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the root privileges. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability exists in the res.php endpoint where the id HTTP POST parameter is not properly sanitized, enabling command injection.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Flir Flir Ax8 Firmware
Flir Flir Ax8
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 1437 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Flir
CVE-2023-29861 9.8 An issue found in FLIR-DVTEL version not specified allows a remote attacker t... CVE-2023-51126 9.8 Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16... CVE-2018-3813 9.8 getConfigExportFile.cgi on FLIR Brickstream 2300 devices 2.0 4.1.53.166 has I... CVE-2022-4364 9.8 A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected b... CVE-2025-6266 9.8 A vulnerability was detected in Teledyne FLIR AX8 up to 1.46. Affected by thi...
View all Flir CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →