CVE-2024-58338
CRITICALAteme Flamingo XL Firmware - OS Command Injection
Title source: ruleDescription
Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the traceroute command. Attackers can exploit the traceroute command to inject shell commands and gain full root access to the device by bypassing the restricted login environment.
Exploits (1)
References (4)
Scores
CVSS v3
10.0
EPSS
0.0006
EPSS Percentile
18.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (1)
ateme/flamingo_xl_firmware
3.2.9
Published
Dec 30, 2025
Tracked Since
Feb 18, 2026