peter bassill · operator
$ cve CVE-2017-20216 JSON

CVE-2017-20216

9.8
CRITICAL · CVSS 3.1 · EPSS 12% (pctl 96)

Patch early

EPSS 12% — above the 10% action threshold.

Description

FLIR Thermal Camera PT-Series firmware version 8.0.0.64 contains multiple unauthenticated remote command injection vulnerabilities in the controllerFlirSystem.php script. Attackers can execute arbitrary system commands as root by exploiting unsanitized POST parameters in the execFlirSystem() function through shell_exec() calls. Exploitation evidence was observed by the Shadowserver Foundation on 2026-01-06 (UTC).

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS12.05% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2026-01-08
Last modified2026-06-17

References

→ the Explorer  ·  watch your stack  ·  NVD