VYPR

Flamingo Xs Firmware

by Ateme

CVEs (2)

  • CVE-2023-53983CriDec 30, 2025
    risk 0.64cvss 9.8epss 0.01

    Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.

  • CVE-2023-36252HigJun 26, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote authenticated attacker to execute arbitrary code and cause a denial of service via a the session expiration function.