CVE-2024-58338
Restricted Shell Escape in Anevia Flamingo XL 3.2.9 Enables Root Access
Publication date: 2025-12-30
Last updated on: 2025-12-30
Assigner: VulnCheck
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| anevia | flamingo_xl | 3.2.9 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-266 | A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Anevia Flamingo XL 3.2.9 is a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment by exploiting the traceroute command. Attackers can inject shell commands through traceroute and gain full root access to the device, bypassing the restricted login environment.
How can this vulnerability impact me? :
The vulnerability can allow an attacker to gain full root access to the affected device remotely. This means the attacker can execute arbitrary commands with the highest privileges, potentially leading to complete system compromise, unauthorized data access, and control over the device.