Restricted Shell Vulnerability in Anevia Flamingo XL 3.2.9
CVE-2024-58338
Key Information:
- Vendor
Ateme
- Status
- Vendor
- CVE Published:
- 30 December 2025
Badges
What is CVE-2024-58338?
Anevia Flamingo XL version 3.2.9 contains a vulnerability that exposes users to severe security risks by allowing remote attackers to escape the sandboxed environment via the traceroute command. This flaw can be exploited to inject malicious shell commands, potentially granting attackers full root access to the device. The restricted login environment is effectively bypassed, enabling unauthorized control over the system, which poses significant implications for data security and device integrity.
Affected Version(s)
Flamingo XL 3.2.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
