Unrated severityNVD Advisory· Published Dec 30, 2025· Updated Jan 16, 2026
Anevia Flamingo XL/XS 3.6.20 Default Credentials Authentication Bypass
CVE-2023-53983
Description
Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.
Affected products
2- Range: 1.3.1
- Ateme/Anevia Flamingo XL/XSv5Range: 3.6.20
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- packetstormsecurity.com/files/172875/Anevia-Flamingo-XL-XS-3.6.x-Default-Hardcoded-Credentials.htmlmitreexploit
- cxsecurity.com/issue/WLB-2023060019mitrethird-party-advisory
- www.ateme.commitrevendor-advisory
- www.vulncheck.com/advisories/anevia-flamingo-xlxs-default-credentials-authentication-bypassmitrethird-party-advisory
- www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5777.phpmitrethird-party-advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/259059mitrevdb-entry
News mentions
0No linked articles in our index yet.