Description
Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.
Problem types
Product status
3.2.9
2.0.3
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5777.php (Zero Science Lab Disclosure (ZSL-2023-5777))
packetstormsecurity.com/...efault-Hardcoded-Credentials.html (Packet Storm Security Exploit Details)
exchange.xforce.ibmcloud.com/vulnerabilities/259059 (IBM X-Force Vulnerability Exchange Entry)
cxsecurity.com/issue/WLB-2023060019 (CXSecurity Vulnerability Listing)
www.ateme.com/ (Ateme Vendor Homepage)
www.vulncheck.com/...fault-credentials-authentication-bypass (VulnCheck Advisory: Anevia Flamingo XL/XS 3.6.20 Default Credentials Authentication Bypass)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.