CVE-2025-6266

CRITICAL

A vulnerability was detected in Teledyne FLIR AX8 up to 1.46. Affected by this vulnerability is an unknown functionality of the file /upload.php. Performing manipulation of the argument File result...

Affects 2 products across 1 vendor.

BCS7.03
CVSS 3.19.8
CVSS v42.1
EPSS0.4%
Percentile34th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-284: Improper Access Control

Software does not restrict or incorrectly restricts access to a resource.

CWE-434: Unrestricted Upload of File with Dangerous Type

Application allows file uploads without validating type, enabling upload of executable code or web shells.

Related Attack Patterns (CAPEC)
CAPEC-478 Modification of Windows Service Configuration
via CWE-284
CAPEC-479 Malicious Root Certificate
via CWE-284
CAPEC-546 Incomplete Data Deletion in a Multi-Tenant Environment
via CWE-284
CAPEC-550 Install New Service
via CWE-284
CAPEC-551 Modify Existing Service
via CWE-284
Show all 18

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in Teledyne FLIR AX8 up to version 1.46 allows for unrestricted file uploads via the /upload.php file, enabling remote attackers to upload malicious files.

BSID: BS-2025-GLOBAL-031385-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-6266?
A critical vulnerability in Teledyne FLIR AX8 up to version 1.46 allows for unrestricted file uploads via the /upload.php file, enabling remote attackers to upload malicious files.
What is the CVSS score for CVE-2025-6266?
CVE-2025-6266 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.4%.
Is CVE-2025-6266 actively exploited?
No confirmed active exploitation of CVE-2025-6266 as of 2026-05-30.
How do I remediate CVE-2025-6266?
Priority: IMMEDIATE.
What systems are affected by CVE-2025-6266?
CVE-2025-6266 affects: Flir, Flir.
Vulnerability Details
CVE IDCVE-2025-6266
BSIDBS-2025-GLOBAL-031385-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2025-06-19
Last Modified2026-04-29
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

A vulnerability was detected in Teledyne FLIR AX8 up to 1.46. Affected by this vulnerability is an unknown functionality of the file /upload.php. Performing manipulation of the argument File results in unrestricted upload. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 1.49.16 addresses this issue. Upgrading the affected component is recommended. The vendor points out: "FLIR AX8 internal web site has been refactored to be able to handle the reported vulnerabilities."

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is exploited by manipulating the 'File' argument in the /upload.php file, allowing for the upload of arbitrary files. This can lead to remote code execution if the uploaded file is executed by the server.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Flir Flir Ax8 Firmware
Flir Flir Ax8
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 423 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashce1236277d90f14d917f208cc5f837435a6aec6f35959199e9ec01fb115a669903e3da2d3c429007531160d9ec52cb5549cee5f5d09d48b62178f009c0417465
Related CVEs affecting Flir
CVE-2022-4364 9.8 A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected b... CVE-2023-29861 9.8 An issue found in FLIR-DVTEL version not specified allows a remote attacker t... CVE-2022-37061 9.8 All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are v... CVE-2018-3813 9.8 getConfigExportFile.cgi on FLIR Brickstream 2300 devices 2.0 4.1.53.166 has I... CVE-2023-51126 9.8 Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16...
View all Flir CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →