Known Vulnerabilities for products from Reolink

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Reolink".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by Reolink can be found at device.report : Reolink

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2022-21801 A denial of service vulnerability exists in the netserver recv_command functionality of reolink RLC-410W v3.0.0.136_20121102.... 7.5 - HIGH 2022-01-28 2022-07-01
CVE-2022-21796 A memory corruption vulnerability exists in the netserver parse_command_list functionality of reolink RLC-410W v3.0.0.136_201... 8.2 - HIGH 2022-01-28 2023-07-24
CVE-2022-21236 An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_201211... 7.5 - HIGH 2022-01-28 2022-07-01
CVE-2022-21217 An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_20121102. A ... 9.8 - CRITICAL 2022-01-28 2023-07-24
CVE-2022-21199 An information disclosure vulnerability exists due to the hardcoded TLS key of reolink RLC-410W v3.0.0.136_20121102. A specia... 5.9 - MEDIUM 2022-01-28 2022-07-01
CVE-2022-21134 A firmware update vulnerability exists in the "update" firmware checks functionality of reolink RLC-410W v3.0.0.136... 7.5 - HIGH 2022-01-28 2022-07-01
CVE-2021-40423 A denial of service vulnerability exists in the cgiserver.cgi API command parser functionality of Reolink RLC-410W v3.0.0.136... 7.5 - HIGH 2022-01-28 2022-07-28
CVE-2021-40419 A firmware update vulnerability exists in the 'factory' binary of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted s... 7.5 - HIGH 2022-01-28 2022-09-30
CVE-2021-40416 An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W... 8.8 - HIGH 2022-01-28 2022-10-19
CVE-2021-40415 An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W... 6.5 - MEDIUM 2022-01-28 2022-10-06
CVE-2021-40414 An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W... 7.1 - HIGH 2022-01-28 2022-06-15
CVE-2021-40413 An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W... 7.1 - HIGH 2022-01-28 2022-06-15
CVE-2021-40412 An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121... 7.2 - HIGH 2022-01-28 2022-07-29
CVE-2021-40411 An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_2012... 7.2 - HIGH 2022-01-28 2022-07-29
CVE-2021-40410 An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_2012... 7.2 - HIGH 2022-01-28 2022-07-29
CVE-2021-40409 An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_2012... 9.8 - CRITICAL 2022-01-28 2022-07-29
CVE-2021-40408 An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_2012... 9.8 - CRITICAL 2022-01-28 2022-07-29
CVE-2021-40407 An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_2012... 9.8 - CRITICAL 2022-01-28 2022-07-29
CVE-2021-40406 A denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.136_2... 7.5 - HIGH 2022-01-28 2022-09-03
CVE-2021-40405 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 6.5 - MEDIUM 2022-04-14 2022-04-25

Known software with vulnerabilities from Reolink

Type Vendor Product Version
HardwareReolinkC1 Pro-
Operating
System
ReolinkC1 Pro Firmware-
HardwareReolinkC2 Pro-
Operating
System
ReolinkC2 Pro Firmware-
HardwareReolinkRlc-410w-
Operating
System
ReolinkRlc-410w Firmware-
HardwareReolinkRlc-422w-
Operating
System
ReolinkRlc-422w Firmware-
HardwareReolinkRlc-511w-
Operating
System
ReolinkRlc-511w Firmware-
HardwareReolinkRlc-520a-
Operating
System
ReolinkRlc-520a Firmware-