Junglewise Threat Intelligence

CVE-2023-53983: Anevia Flamingo XL/XS weak default credentials authentication bypass

CVE-2023-53983 · Severity: critical · CVSS 9.8 · Published 2025-12-30

Executive brief

Anevia Flamingo XL/XS is an IPTV head-end product used by hospitality and corporate service providers to capture and stream live TV content over IP networks. The device ships with easily guessable default administrative credentials (such as admin:paris and root:anevia) that allow unauthenticated remote attackers to gain full system control without any authentication bypass techniques, potentially enabling complete compromise of broadcast infrastructure and customer access.

Technical details

This vulnerability is a credential weakness / authentication bypass flaw in which the Anevia Flamingo XL/XS devices are deployed with hard-coded default administrative credentials across multiple interfaces (SSH, web administration, and OEM interfaces). The vulnerable component is the authentication system itself, which fails to enforce credential rotation. Attack vector is network-based and requires no preconditions beyond network access to the device; attackers can attempt login using well-known credential pairs (root:anevia, admin:paris, enable:paris, monitor:anevia, etc.) to gain immediate remote administrative access. Successful exploitation enables full system control including modification of broadcast streams, interruption of service, and potential access to subscriber data. The vulnerability affects versions 3.6.20, 3.2.9 and related software versions; mitigation requires changing all default credentials immediately upon deployment.

Affected products

  • Anevia Flamingo XL 3.6.20, 3.2.9
  • Anevia Flamingo XS 3.6.20, 3.2.9

Timeline

  • 2023-06-13: disclosed: Vulnerability publicly disclosed; advisory ZSL-2023-5777
  • 2023-12-30: advisory: CVE-2023-53983 assigned and published to NVD

References