CVE-2023-53983
Anevia Flamingo XL/XS 3.6.20 Default Credentials Authentication Bypass
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.3EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
30 Dec 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://cxsecurity.com/issue/WLB-2023060019https://exchange.xforce.ibmcloud.com/vulnerabilities/259059https://packetstormsecurity.com/files/172875/Anevia-Flamingo-XL-XS-3.6.x-Default-Hardcoded-Credentials.htmlhttps://www.ateme.com/https://www.vulncheck.com/advisories/anevia-flamingo-xlxs-default-credentials-authentication-bypasshttps://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5777.php