Ateme develops video streaming and transcoding appliances, primarily the Flamingo series alongside its SoapLive platform, which represent a niche footprint in the media-delivery infrastructure landscape. The disclosed vulnerabilities center on operational weaknesses including OS command injection, hard-coded credentials, insufficient session management, and server-side request forgery, reflecting the network-exposed and privileged nature of these devices. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ateme over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-58338CRITICAL Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the traceroute command. Attackers can ex | Dec 30, 2025 | 10.0 | 32 | NO | NO |
CVE-2023-53983CRITICAL Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded cred | Dec 30, 2025 | 9.8 | 31 | NO | NO |
CVE-2023-36252HIGH An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote authenticated attacker to execute arbitrary code and cause a denial of service via a the session expiration fu | Jun 26, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-53893MEDIUM Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter that allows attackers to bypass network restrictions | Dec 15, 2025 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ateme.
Media articles that mention a CVE ID that affects a product developed by Ateme — matched by CVE ID, not by vendor name.