important · Physical — Robotics
Unauthenticated path traversal exposes credentials and configuration on PackBot and FirstLook robots.
Affects
Teledyne FLIR Aware2 software used by PackBot and FirstLook unmanned ground robots.
A remote client can read arbitrary files through the Aware2 web service, including stored credentials and operational configuration.
Detail and 2 sources
Mandiant claims complete compromise and remote code execution, but the public material does not disclose the transition from file reading to execution.
Updated software is published, but the fix itself was not inspected for this brief.
Chain to watch
Reach the Aware2 web service without authenticating.→↓Use traversal components to read credentials and configuration.→↓Establish whether the exposed material yields code execution on each robot family.→↓The public record does not establish the claimed transition from arbitrary file reading to code execution.
Unverified chainObtain the fixed build or proof of concept and reproduce that transition on PackBot and FirstLook.