VYPR
Unrated severityNVD Advisory· Published Jan 28, 2022· Updated Apr 15, 2025

CVE-2021-40406

CVE-2021-40406

Description

A denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to prevent users from logging in. An attacker can send an HTTP request to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A denial of service vulnerability in Reolink RLC-410W camera's session creation allows an attacker to prevent user logins via a specially-crafted HTTP request.

Vulnerability

The vulnerability resides in the cgiserver.cgi session creation functionality of the Reolink RLC-410W camera running firmware version v3.0.0.136_20121102. The camera maintains an in-memory session list that is updated by cgiserver.cgi, which removes out-of-date or invalid sessions. A specially-crafted HTTP request can pollute this list with a non-removable session, eventually filling the session list and preventing new logins [1].

Exploitation

An unauthenticated attacker with network access to the camera can send a crafted HTTP request. The cgiserver.cgi parses the request body as a JSON array of commands; by providing a malicious command sequence, the attacker can create a session entry that cannot be removed. No user interaction is required [1].

Impact

Successful exploitation results in a denial of service condition where legitimate users are unable to log into the camera. The attack does not affect confidentiality or integrity. The CVSSv3 score is 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) [1].

Mitigation

As of the publication date (2022-01-28), no firmware update or workaround has been released by Reolink. Users should monitor the vendor's support channels for a patch. The affected model (RLC-410W) is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • reolink/RLC-410Wdescription
  • Reolink/RLC-410Wllm-fuzzy
    Range: = 3.0.0.136_20121102

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.