FLIR Brickstream 3D+ 2.1.742.1842 contains an...
High severity
Unreviewed
Published
Dec 24, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Dec 24, 2025
Published to the GitHub Advisory Database
Dec 24, 2025
FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability in the ExportConfig REST API that allows attackers to download sensitive configuration files. Attackers can exploit the getConfigExportFile.cgi endpoint to retrieve system configurations, potentially enabling authentication bypass and privilege escalation.
References