CVE-2024-58338

CRITICAL

Ateme Flamingo XL Firmware - OS Command Injection

Title source: rule

Description

Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the traceroute command. Attackers can exploit the traceroute command to inject shell commands and gain full root access to the device by bypassing the restricted login environment.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textremotehardware
https://www.exploit-db.com/exploits/51516

Scores

CVSS v3 10.0
EPSS 0.0006
EPSS Percentile 18.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
ateme/flamingo_xl_firmware 3.2.9
Published Dec 30, 2025
Tracked Since Feb 18, 2026