QID 591175
Date Published: 2022-11-11
QID 591175: Reolink RLC-410W cgiserver.cgi cgi_check_ability improper access control Multiple Vulnerabilities (TALOS-2021-1425)
Tested Versions
Reolink RLC-410W v3.0.0.136_20121102
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
Multiple incorrect default permissions vulnerabilities exist in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
Solution
Customers are advised to refer to CERT MITIGATIONS section TALOS-2021-1425 for affected packages and patching details.
Vendor References
- TALOS-2021-1425 -
talosintelligence.com/vulnerability_reports/TALOS-2021-1425
CVEs related to QID 591175
Software Advisories
| Advisory ID | Software | Component | Link |
|---|