QID 591048
Date Published: 2022-09-16
QID 591048: Reolink RLC-410W Denial of Service (DoS) Multiple Vulnerabilities (TALOS-2021-1421)
Tested Versions
reolink RLC-410W v3.0.0.136_20121102
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.
Solution
Customers are advised to refer to CERT MITIGATIONS section TALOS-2021-1421 for affected packages and patching details.
Vendor References
- TALOS-2021-1421 -
talosintelligence.com/vulnerability_reports/TALOS-2021-1421
CVEs related to QID 591048
CVE-2021-44354 | CVE-2021-44355 | CVE-2021-44356 | CVE-2021-44357 | CVE-2021-44358 | CVE-2021-44359 | CVE-2021-44360 | CVE-2021-44361 | CVE-2021-44362 | CVE-2021-44363 | CVE-2021-44364 | CVE-2021-44365 | CVE-2021-44366 | CVE-2021-44367 | CVE-2021-44368 | CVE-2021-44369 | CVE-2021-44370 | CVE-2021-44371 | CVE-2021-44372 | CVE-2021-44373 | CVE-2021-44374 | CVE-2021-44375 | CVE-2021-44376 | CVE-2021-44377 | CVE-2021-44378 | CVE-2021-44379 | CVE-2021-44380 | CVE-2021-44381 | CVE-2021-44382 | CVE-2021-44383 | CVE-2021-44384 | CVE-2021-44385 | CVE-2021-44386 | CVE-2021-44387 | CVE-2021-44388 | CVE-2021-44389 | CVE-2021-44390 | CVE-2021-44391 | CVE-2021-44392 | CVE-2021-44393 | CVE-2021-44394 | CVE-2021-44395 | CVE-2021-44396 | CVE-2021-44397 | CVE-2021-44398 | CVE-2021-44399 | CVE-2021-44400 | CVE-2021-44401 | CVE-2021-44402 | CVE-2021-44403 | CVE-2021-44404 | CVE-2021-44405 | CVE-2021-44406 | CVE-2021-44407 | CVE-2021-44408 | CVE-2021-44409 | CVE-2021-44410 | CVE-2021-44411 | CVE-2021-44412 | CVE-2021-44413 | CVE-2021-44414 | CVE-2021-44415 | CVE-2021-44416 | CVE-2021-44417 | CVE-2021-44418 | CVE-2021-44419 |
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| TALOS-2021-1421 |
|