CVE-2023-53983: Ateme Flamingo Xl Firmware

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.

Affected products

  • Ateme Flamingo Xl Firmware: version 3.2.9 only; version 3.6.20 only
  • Ateme Flamingo Xs Firmware: version 3.2.9 only; version 3.6.20 only
  • Ateme Soaplive: version 2.0.3 only; version 2.4.1 only
  • Ateme Soapsystem: version 1.3.1 only

Published 2025-12-30. Last modified 2026-09-24.