{"api_version":"1","generated_at":"2026-07-25T00:10:07+00:00","cve":"CVE-2021-40149","urls":{"html":"https://cve.report/CVE-2021-40149","api":"https://cve.report/api/cve/CVE-2021-40149.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-40149","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-40149"},"summary":{"title":"CVE-2021-40149","description":"The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2022-07-17 22:15:00","updated_at":"2022-07-27 17:21:00"},"problem_types":["CWE-552"],"metrics":[],"references":[{"url":"https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2021-40149.txt","name":"https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2021-40149.txt","refsource":"MISC","tags":[],"title":"advisories/CVE-2021-40149.txt at master · MrTuxracer/advisories · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://packetstormsecurity.com/files/167407/Reolink-E1-Zoom-Camera-3.0.0.716-Private-Key-Disclosure.html","name":"http://packetstormsecurity.com/files/167407/Reolink-E1-Zoom-Camera-3.0.0.716-Private-Key-Disclosure.html","refsource":"MISC","tags":[],"title":"Reolink E1 Zoom Camera 3.0.0.716 Private Key Disclosure ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2022/Jun/0","name":"http://seclists.org/fulldisclosure/2022/Jun/0","refsource":"MISC","tags":[],"title":"Full Disclosure: [CVE-2021-40149] Reolink E1 Zoom Camera <= 3.0.0.716 Unauthenticated Private Key Disclosure","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-40149","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-40149","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"40149","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"reolink","cpe5":"e1_zoom","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"40149","vulnerable":"1","versionEndIncluding":"3.0.0.716","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"reolink","cpe5":"e1_zoom_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-40149","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"http://packetstormsecurity.com/files/167407/Reolink-E1-Zoom-Camera-3.0.0.716-Private-Key-Disclosure.html","url":"http://packetstormsecurity.com/files/167407/Reolink-E1-Zoom-Camera-3.0.0.716-Private-Key-Disclosure.html"},{"refsource":"MISC","name":"http://seclists.org/fulldisclosure/2022/Jun/0","url":"http://seclists.org/fulldisclosure/2022/Jun/0"},{"refsource":"MISC","name":"https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2021-40149.txt","url":"https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2021-40149.txt"}]}},"nvd":{"publishedDate":"2022-07-17 22:15:00","lastModifiedDate":"2022-07-27 17:21:00","problem_types":["CWE-552"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.2,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:reolink:e1_zoom_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"3.0.0.716","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:reolink:e1_zoom:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"40149","Ordinal":"215865","Title":"CVE-2021-40149","CVE":"CVE-2021-40149","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"40149","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}