Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wm7p-2wcf-h9qh

Опубликовано: 31 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 9.8

Описание

Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the traceroute command. Attackers can exploit the traceroute command to inject shell commands and gain full root access to the device by bypassing the restricted login environment.

Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the traceroute command. Attackers can exploit the traceroute command to inject shell commands and gain full root access to the device by bypassing the restricted login environment.

EPSS

Процентиль: 32%
0.00123
Низкий

8.6 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-266
CWE-78

Связанные уязвимости

CVSS3: 10
nvd
около 1 месяца назад

Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the traceroute command. Attackers can exploit the traceroute command to inject shell commands and gain full root access to the device by bypassing the restricted login environment.

CVSS3: 7.2
fstec
почти 3 года назад

Уязвимость микропрограммного обеспечения IPTV-станций Flamingo XL, связанная с недостатками разграничения доступа, позволяющая нарушителю обойти защитный механизм песочницы, повысить свои привилегии и выполнить произвольные команды

EPSS

Процентиль: 32%
0.00123
Низкий

8.6 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-266
CWE-78