QID 591098
Date Published: 2022-10-11
QID 591098: Reolink RLC-410W netserver parse_command_list memory corruption Vulnerability (TALOS-2022-1451)
Tested Versions
Reolink RLC-410W v3.0.0.136_20121102
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
A memory corruption vulnerability exists in the netserver parse_command_list functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to an out-of-bounds write. An attacker can send an HTTP request to trigger this vulnerability.
Solution
Customers are advised to refer to CERT MITIGATIONS section TALOS-2022-1451 for affected packages and patching details.
Vendor References
- TALOS-2022-1451 -
talosintelligence.com/vulnerability_reports/TALOS-2022-1451
CVEs related to QID 591098
Software Advisories
| Advisory ID | Software | Component | Link |
|---|