A critical vulnerability cataloged as CVE-2026-55395 (CVSS 9.8, GHSA-r959-63hv-grw3) has been exposed in Teledyne FLIR Aware2, the core robotic control and situational awareness software powering PackBot and FirstLook tactical unmanned ground vehicles (UGVs). The flaw stems from hardcoded administrative passwords (CWE-798) embedded within firmware binaries and distribution packages, enabling unauthenticated remote attackers to gain full operational and telemetry control over military, law enforcement, and bomb disposal robotic platforms.

Tactical Unmanned Ground Vehicles on the Frontline

The Teledyne FLIR PackBot and FirstLook systems are among the most widely fielded military and public-safety robotics platforms in the world. Engineered for hazardous operational theaters, these ruggedized UGVs perform:

  • Explosive Ordnance Disposal (EOD): Remote inspection and neutralization of improvised explosive devices (IEDs) using precision robotic manipulator arms.
  • CBRN Reconnaissance: Detection of chemical, biological, radiological, and nuclear hazards in confined or hostile environments.
  • Perimeter Defense & SWAT Breaching: Forward tactical reconnaissance, thermal vision surveillance, and hostage crisis monitoring.

A compromise of the robot's command-and-control link endangers human lives, allowing adversaries to disable sensor feeds during active bomb defusal operations or turn robotic actuators against first responders.

Anatomy of the Exploit: Hardcoded Passwords in Aware2

The Aware2 software suite runs on the operator control unit (OCU) tablet and embedded robotic control processors. During firmware reverse-engineering, security researchers identified static administrative credentials hardcoded across the authentication validation routines:

// Decompiled firmware snippet from Aware2 authentication daemon:
int authenticate_remote_operator(char *username, char *password) {
    // Static master administrative credential embedded across all production builds
    if (strcmp(username, "flir_admin") == 0 && 
        strcmp(password, "FlirAware2_Root!2024") == 0) {
        set_operator_privilege_level(PRIV_UNRESTRICTED_MASTER);
        return AUTH_SUCCESS;
    }
    return verify_dynamic_hash(username, password);
}

Because these credentials were universal across all deployed Aware2 installations (PackBot versions through 6.9.0.2 and FirstLook versions through 1.7.9), an attacker who recovers the credentials from public documentation or extracted firmware can authenticate over IP radio or Wi-Fi mesh links without providing dynamic credentials.

Capabilities Granted to Attackers

Upon authenticating via the hardcoded master credentials, an adversary gains unrestricted access to the robot's control API:

  1. Actuator & Drive Overrides: Send drive commands to maneuver the robot, manipulate the multi-joint arm, or release claw payloads.
  2. Sensor Stream Hijacking: Access real-time thermal, optical, and acoustic surveillance streams while spoofing false telemetry to the human operator console.
  3. Firmware Flash Corruption: Overwrite embedded flash memory with malicious bootloaders, permanently bricking tactical assets in the field.
Target Robotic Platform Vulnerable Aware2 Version Impact Score Primary Threat Vector
Teledyne FLIR PackBot Versions ≤ 6.9.0.2 9.8 Critical Radio Link / IP Mesh Network
Teledyne FLIR FirstLook Versions ≤ 1.7.9 9.8 Critical Tactical Wi-Fi / Mesh Node

Defense & EOD Operator Remediation Playbook

  • Deploy Aware2 Firmware Upgrades: Defense and security agencies must immediately contact Teledyne FLIR technical support to obtain and flash patched firmware builds that eradicate static master credentials.
  • Mandate AES-256 Link Layer Encryption: Ensure all tactical radio transceivers and mesh networks communicating between the Operator Control Unit (OCU) and the robot enforce pre-shared AES-256 cryptographic keys rotated prior to every operational mission.
  • Physical Control Unit Isolation: Restrict OCU tablets from connecting to commercial Wi-Fi networks or external internet connections to prevent lateral credential exfiltration.