---
id: CVE-2023-53983
title: >-
  Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak
  default administrative credentials that can be easily guessed
summary: >-
  Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak
  default administrative credentials that can be easily guessed. Attackers can
  leverage these hard-coded credentials to gain full remote system control
  without comple…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-798
vendor: ateme
product: soaplive
affected:
  - flamingo_xl_firmware = 3.2.9
  - flamingo_xl_firmware = 3.6.20
  - flamingo_xs_firmware = 3.2.9
  - flamingo_xs_firmware = 3.6.20
  - soaplive = 2.0.3
  - soaplive = 2.4.1
  - soapsystem = 1.3.1
published: '2025-12-30'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T23:10:00.133'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-53983'
references:
  - url: 'https://cxsecurity.com/issue/WLB-2023060019'
    label: disclosure@vulncheck.com
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/259059'
    label: disclosure@vulncheck.com
  - url: >-
      https://packetstormsecurity.com/files/172875/Anevia-Flamingo-XL-XS-3.6.x-Default-Hardcoded-Credentials.html
    label: disclosure@vulncheck.com
  - url: 'https://www.ateme.com/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/anevia-flamingo-xlxs-default-credentials-authentication-bypass
    label: disclosure@vulncheck.com
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5777.php'
    label: disclosure@vulncheck.com
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5777.php'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00657
epssPercentile: 0.49234
ingestedAt: '2026-09-24T23:55:20.489Z'
---

## Overview

Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.

## Affected

- `flamingo_xl_firmware = 3.2.9`
- `flamingo_xl_firmware = 3.6.20`
- `flamingo_xs_firmware = 3.2.9`
- `flamingo_xs_firmware = 3.6.20`
- `soaplive = 2.0.3`
- `soaplive = 2.4.1`
- `soapsystem = 1.3.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
