MachineSense FeverWarn
FeverWarn thermal screening devices (ESP32, RaspberryPi, and DataHub variants) contain multiple critical vulnerabilities: missing authentication (CWE-306), hardcoded credentials (CWE-798), improper access controls (CWE-284), and missing input validation (CWE-20). These flaws allow remote attackers without credentials to extract user data, execute arbitrary code, or gain full control of the devices over the network. MachineSense discontinued FeverWarn before the end of the pandemic and will not provide patches. The product is no longer available, and the vendor is not aware of current users.
- Network access to the FeverWarn device (direct or via Internet if exposed)
- No valid credentials or authentication required
- Device must be connected to a network and running the vulnerable firmware
Patching may require device reboot — plan for process interruption
/api/v1/advisories/fec48653-585a-44b4-ac20-65b9821c646aGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.