High severity7.1NVD Advisory· Published Jan 28, 2022· Updated Jun 17, 2026
CVE-2021-40413
CVE-2021-40413
Description
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The UpgradePrepare is the API that checks if a provided filename identifies a new version of the RLC-410W firmware. If the version is new, it would be possible, allegedly, to later on perform the Upgrade. An attacker can send an HTTP request to trigger this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- reolink/RLC-410Wdescription
- cpe:2.3:o:reolink:rlc-410w_firmware:3.0.0.136_20121102:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- talosintelligence.com/vulnerability_reports/TALOS-2021-1425nvdExploitTechnical DescriptionThird Party Advisory
News mentions
0No linked articles in our index yet.