CVE-2021-40409
Description
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->password variable, that has the value of the password parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An OS command injection vulnerability in Reolink RLC-410W's SetDdns API allows authenticated attackers to execute arbitrary commands via the password parameter.
Vulnerability
An OS command injection vulnerability exists in the device network settings functionality of Reolink RLC-410W v3.0.0.136_20121102. The SetDdns API processes the password parameter without proper validation, leading to command injection in the set_dds_config function. The affected parameter is password within the DDNS settings [1].
Exploitation
An attacker must have high privileges (authenticated access to the camera's API) and network connectivity. They send a specially crafted HTTP request to the SetDdns API with a malicious payload in the password field. When the device applies the DDNS settings, the injected command is executed [1].
Impact
Successful exploitation leads to arbitrary OS command execution with root privileges, resulting in full compromise of confidentiality, integrity, and availability. The CVSSv3 score is 9.1 (Critical) [1].
Mitigation
As of the report date, no official patch was available. Users should monitor vendor updates for a fixed firmware version. Restricting network access to the API can reduce risk. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- reolink/RLC-410Wdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- talosintelligence.com/vulnerability_reports/TALOS-2021-1424mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.