VYPR
Unrated severityNVD Advisory· Published Jan 28, 2022· Updated Apr 15, 2025

CVE-2021-40416

CVE-2021-40416

Description

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. All the Get APIs that are not included in cgi_check_ability are already executable by any logged-in users. An attacker can send an HTTP request to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Incorrect default permission in Reolink RLC-410W cgiserver.cgi allows logged-in users to execute privileged APIs, leading to denial of service.

Vulnerability

The vulnerability resides in the cgi_check_ability function of cgiserver.cgi on Reolink RLC-410W firmware version v3.0.0.136_20121102. The function incorrectly handles permission checks for API commands, allowing any logged-in user to execute APIs that are not explicitly listed in the permission table (i.e., all Get APIs not included in the cgi_check_ability logic). This stems from an improper default access control (CWE-284) where the permission check defaults to granting access when the API is not found in the internal command table [1].

Exploitation

An attacker needs network access to the camera and valid login credentials (low-privileged user account). Once authenticated, the attacker can send specially crafted HTTP requests to any Get API that is not subject to the cgi_check_ability permission check. The advisory notes that all Get APIs not included in cgi_check_ability are already executable by any logged-in users, making exploitation straightforward with just an HTTP request [1].

Impact

Successful exploitation allows the attacker to trigger unintended API calls, leading to denial of service (as per CVSS score 7.1, with high availability impact). The confidentiality impact is none, and integrity impact is low, meaning the attacker can disrupt device operation but cannot access sensitive data or modify critical settings without additional vulnerabilities [1].

Mitigation

As of the publication date, no firmware update or patch has been released by Reolink to address this vulnerability. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Affected users should monitor vendor advisories for a future fix and consider restricting network access to the camera until a patch is available [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • reolink/RLC-410Wdescription
  • Reolink/RLC-410Wllm-fuzzy
    Range: = 3.0.0.136_20121102

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.