CVE-2022-37061
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root ...
Affects 2 products across 1 vendor.
Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
FLIR AX8 thermal sensor cameras up to version 1.46.16 are vulnerable to Remote Command Injection, allowing attackers to execute arbitrary shell commands as the root user.
BSID: BS-2022-GLOBAL-157213-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2022-37061?
What is the CVSS score for CVE-2022-37061?
Is CVE-2022-37061 actively exploited?
How do I remediate CVE-2022-37061?
What systems are affected by CVE-2022-37061?
| CVE ID | CVE-2022-37061 |
|---|---|
| BSID | BS-2022-GLOBAL-157213-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2022-08-18 |
| Last Modified | 2025-10-17 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Source | NVD |
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php endpoint. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the root privileges. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.
Source: NIST NVD / MITRE CVE Database
The vulnerability exists in the res.php endpoint where the id HTTP POST parameter is not properly sanitized, enabling command injection.
Exploitation Likelihood: CRITICAL
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | ⚠ Available — Reference |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
Critical Severity - Know Your Exposure
A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →