CVE-2023-53983
moderate-risk
Published 2025-12-30
Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.
Do I need to act?
-
0.58% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (7)
Flamingo Xl Firmware
Flamingo Xl Firmware
Flamingo Xs Firmware
Flamingo Xs Firmware
Soaplive
Soaplive
Soapsystem
Affected Vendors
References (7)
Third Party Advisory
https://cxsecurity.com/issue/WLB-2023060019
Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/259059
Third Party Advisory
https://packetstormsecurity.com/files/172875/Anevia-Flamingo-XL-XS-3.6.x-Default...
Product
https://www.ateme.com/
Third Party Advisory
https://www.vulncheck.com/advisories/anevia-flamingo-xlxs-default-credentials-au...
48
/ 100
moderate-risk
Severity
32/34 · Critical
Exploitability
2/34 · Minimal
Exposure
14/34 · Moderate