CVE-2023-53983
Severity CVSS v4.0:
CRITICAL
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
30/12/2025
Last modified:
31/12/2025
Description
Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://cxsecurity.com/issue/WLB-2023060019
- https://exchange.xforce.ibmcloud.com/vulnerabilities/259059
- https://packetstormsecurity.com/files/172875/Anevia-Flamingo-XL-XS-3.6.x-Default-Hardcoded-Credentials.html
- https://www.ateme.com/
- https://www.vulncheck.com/advisories/anevia-flamingo-xlxs-default-credentials-authentication-bypass
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5777.php



