QID 591049
Date Published: 2022-09-16
QID 591049: Reolink RLC-410W device network settings OS command injection Multiple Vulnerabilities (TALOS-2021-1424)
Tested Versions
Reolink RLC-410W v3.0.0.136_20121102
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
Multiple os command injection vulnerabilities exist in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.
Solution
Customers are advised to refer to CERT MITIGATIONS section TALOS-2021-1424 for affected packages and patching details.
Vendor References
CVEs related to QID 591049
Software Advisories
| Advisory ID | Software | Component | Link |
|---|