CVE-2017-20216

CRITICAL

FLIR Thermal Camera PT-Series firmware version 8.0.0.64 contains multiple unauthenticated remote command injection vulnerabilities in the controllerFlirSystem.php script. Attackers can execute arbi...

Affects 0 products across 3 vendors.

BCS7.33
CVSS 3.19.8
CVSS v49.3
EPSS10.6%
Percentile95th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-78: OS Command Injection

Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.

Related Attack Patterns (CAPEC)
CAPEC-43 Exploiting Multiple Input Interpretation Layers
via CWE-78
CAPEC-108 Command Line Execution through SQL Injection
via CWE-78
CAPEC-6 Argument Injection
via CWE-78
CAPEC-15 Command Delimiters
via CWE-78
CAPEC-88 OS Command Injection
via CWE-78

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

FLIR Thermal Camera PT-Series firmware version 8.0.0.64 is vulnerable to unauthenticated remote command injection, allowing attackers to execute arbitrary system commands as root.

BSID: BS-2026-GLOBAL-118594-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2017-20216?
FLIR Thermal Camera PT-Series firmware version 8.0.0.64 is vulnerable to unauthenticated remote command injection, allowing attackers to execute arbitrary system commands as root.
What is the CVSS score for CVE-2017-20216?
CVE-2017-20216 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 10.6%.
Is CVE-2017-20216 actively exploited?
No confirmed active exploitation of CVE-2017-20216 as of 2026-05-30.
How do I remediate CVE-2017-20216?
Priority: IMMEDIATE.
What systems are affected by CVE-2017-20216?
CVE-2017-20216 affects: Flir, Foundation, Script.
Vulnerability Details
CVE IDCVE-2017-20216
BSIDBS-2026-GLOBAL-118594-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-01-08
Last Modified2026-04-15
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

FLIR Thermal Camera PT-Series firmware version 8.0.0.64 contains multiple unauthenticated remote command injection vulnerabilities in the controllerFlirSystem.php script. Attackers can execute arbitrary system commands as root by exploiting unsanitized POST parameters in the execFlirSystem() function through shell_exec() calls. Exploitation evidence was observed by the Shadowserver Foundation on 2026-01-06 (UTC).

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Attackers can exploit unsanitized POST parameters in the execFlirSystem() function within the controllerFlirSystem.php script, which uses shell_exec() to execute commands. This vulnerability can be exploited remotely without authentication.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Flir —
Foundation —
Script —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 198 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashacacfbc659b70fd1e590e0ab1071a20f7404fa01956d5369b7448faebc487788c0f73659ccf675d3ed77109df82e1204b8a0360dd141ba7094fb4e26578bb614
Related CVEs affecting Flir
CVE-2022-4364 9.8 A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected b... CVE-2023-29861 9.8 An issue found in FLIR-DVTEL version not specified allows a remote attacker t... CVE-2022-37061 9.8 All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are v... CVE-2018-3813 9.8 getConfigExportFile.cgi on FLIR Brickstream 2300 devices 2.0 4.1.53.166 has I... CVE-2023-51126 9.8 Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16...
View all Flir CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →