← Back

Ateme

ateme

4 CVEs • 7 products

Products (7)

Click to collapse
Toggle
Titan File
titan_file
Soaplive
soaplive
Soapsystem
soapsystem
Flamingo Xl
flamingo_xl
Flamingo Xs
flamingo_xs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ateme
1Flamingo Xl Firmware
Jun 17, 2026
Dec 30, 2025
8.6 HIGH· v4
10.0 CRITICAL· v3
N/A· v2
Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the traceroute command. Attackers can exploit the traceroute command to inject s...Show more
Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the traceroute command. Attackers can exploit the traceroute command to inject shell commands and gain full root access to the device by bypassing the restricted login environment.Show less
1Ateme
4Flamingo Xl Firmware
Flamingo Xs FirmwareSoaplive+1 more
Jun 17, 2026
Dec 30, 2025
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system contr...Show more
Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.Show less
1Ateme
1Titan File
Jun 17, 2026
Dec 15, 2025
5.3 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter that allows attackers to bypass network restrictions. Attackers can exploit the unvalidated...Show more
Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter that allows attackers to bypass network restrictions. Attackers can exploit the unvalidated parameter to initiate file, service, and network enumeration by forcing the application to make HTTP, DNS, or file requests to arbitrary destinations.Show less
1Ateme
2Flamingo Xl Firmware
Flamingo Xs Firmware
Jun 17, 2026
Jun 26, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote authenticated attacker to execute arbitrary code and cause a denial of service via a the session expiration function.