PT-2025-54258 · Anevia · Anevia Flamingo Xl/Xs

Published

2023-04-13

·

Updated

2026-01-14

·

CVE-2024-58338

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Anevia Flamingo XL version 3.2.9
Description The Flamingo XL IPTV station firmware contains flaws in access control. Exploitation of this issue allows a remote attacker to bypass the sandboxing protection mechanism, escalate privileges, and execute arbitrary commands. The traceroute command can be exploited to inject shell commands and gain full root access to the device, bypassing the restricted login environment.
Recommendations Versions prior to 3.2.9 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Incorrect Privilege Assignment

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2026-00333
CVE-2024-58338

Affected Products

Anevia Flamingo Xl/Xs