Anevia Flamingo XL 3.2.9 contains a restricted shell...
High severity
Unreviewed
Published
Dec 31, 2025
to the GitHub Advisory Database
•
Updated Jan 13, 2026
Description
Published by the National Vulnerability Database
Dec 30, 2025
Published to the GitHub Advisory Database
Dec 31, 2025
Last updated
Jan 13, 2026
Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the traceroute command. Attackers can exploit the traceroute command to inject shell commands and gain full root access to the device by bypassing the restricted login environment.
References