FLIR Systems AX8 Cameras Cross-site Scripting (CVE-2022-37063)

medium Tenable OT Security Plugin ID 505196

Synopsis

The remote OT asset is affected by a vulnerability.

Description

All FLIR AX8 thermal sensor cameras versions up to and including 1.46.16 are vulnerable to Cross Site Scripting (XSS) due to improper input sanitization. An authenticated remote attacker can execute arbitrary JavaScript code in the web management interface. A successful exploit could allow the attacker to insert malicious JavaScript code. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

https://gist.github.com/Nwqda/9e16852ab7827dc62b8e44d6180a6899

https://www.flir.com/products/ax8-automation/

Plugin Details

Severity: Medium

ID: 505196

File Name: tenable_ot_flirsystems_CVE-2022-37063.nasl

Version: 1.1

Type: remote

Family: Tenable.ot

Published: 2/19/2026

Updated: 2/19/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 3.8

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Vulnerability Information

CPE: cpe:/o:flir:flir_ax8_firmware

Required KB Items: Tenable.ot/FLIRSystems

Exploit Ease: No known exploits are available

Patch Publication Date: 8/18/2022

Vulnerability Publication Date: 8/18/2022

Reference Information

CVE: CVE-2022-37063

CWE: 79