vendor:
Flamingo XL
by:
LiquidWorm
7.5
CVSS
HIGH
Authenticated Root Remote Code Execution
CWE
Product Name: Flamingo XL
Affected Version From: 3.6.20, 3.2.9 Hardware revision 1.1, 1.0 SoapLive 2.4.1, 2.0.3 SoapSystem 1.3.1
Affected Version To:
Patch Exists: No
Related CWE:
CPE:
Platforms Tested: GNU/Linux 3.1.4 (x86_64) Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8g DAV/2 PHP/5.3.6
2023
Anevia Flamingo XL 3.6.20 – Authenticated Root Remote Code Execution
The affected device suffers from authenticated remote code execution vulnerability. A remote attacker can exploit this issue and execute arbitrary system commands granting her system access with root privileges.
Mitigation:
No mitigation or remediation mentioned