VYPR
Unrated severityNVD Advisory· Published Jan 28, 2022· Updated Apr 15, 2025

CVE-2021-40409

CVE-2021-40409

Description

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->password variable, that has the value of the password parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An OS command injection vulnerability in Reolink RLC-410W's SetDdns API allows authenticated attackers to execute arbitrary commands via the password parameter.

Vulnerability

An OS command injection vulnerability exists in the device network settings functionality of Reolink RLC-410W v3.0.0.136_20121102. The SetDdns API processes the password parameter without proper validation, leading to command injection in the set_dds_config function. The affected parameter is password within the DDNS settings [1].

Exploitation

An attacker must have high privileges (authenticated access to the camera's API) and network connectivity. They send a specially crafted HTTP request to the SetDdns API with a malicious payload in the password field. When the device applies the DDNS settings, the injected command is executed [1].

Impact

Successful exploitation leads to arbitrary OS command execution with root privileges, resulting in full compromise of confidentiality, integrity, and availability. The CVSSv3 score is 9.1 (Critical) [1].

Mitigation

As of the report date, no official patch was available. Users should monitor vendor updates for a fixed firmware version. Restricting network access to the API can reduce risk. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • reolink/RLC-410Wdescription
  • Reolink/RLC-410Wllm-fuzzy
    Range: = v3.0.0.136_20121102

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.