CVE-2026-55393

Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot and FirstLook robots running this software via path traversal.

  • Published Oct 1, 2026
  • CVSS 10.0 critical
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-55393 at the National Vulnerability Database