QID 591209
Date Published: 2022-11-24
QID 591209: Reolink RLC-410W cgiserver.cgi Login authentication bypass Vulnerability (TALOS-2021-1420)
AFFECTED PRODUCTS
Reolink RLC-410W v3.0.0.136_20121102
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to authentication bypass. An attacker can send an HTTP request to trigger this vulnerability.
Solution
Customers are advised to refer to CERT MITIGATIONS section TALOS-2021-1420 for affected packages and patching details.
Vendor References
- TALOS-2021-1420 -
talosintelligence.com/vulnerability_reports/TALOS-2021-1420
CVEs related to QID 591209
Software Advisories
| Advisory ID | Software | Component | Link |
|---|