Cybercriminals could access the live feed and conduct remote code execution in a thermal security camera if it was made by FLIR Systems. Flaws included a way for threat actors to download and read FLIR operating system (OS) files using an API associated with the devices, along with hardcoded credentials and the potential for information disclosure. FLIR has yet to offer a patch or other fix for the vulnerabilities; FLIR is now conducting its own investigation. The irony is that a thermal-imaging camera is supposed to make a physical environment more secure by offering monitoring capabilities.”]

