CVE-2021-44359
Description
A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetCrop param is not object. An attacker can send an HTTP request to trigger this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A specially-crafted HTTP request to the JSON command parser of Reolink RLC-410W v3.0.0.136_20121102 causes a denial of service via device reboot.
Vulnerability
The vulnerability exists in the cgiserver.cgi JSON command parser of the Reolink RLC-410W WiFi security camera, firmware version v3.0.0.136_20121102. The SetCrop parameter is not properly validated as an object, leading to improper input validation (CWE-20). A specially-crafted HTTP request can trigger a reboot of the device [1].
Exploitation
An attacker can exploit this vulnerability by sending a malicious HTTP request to the camera's API without requiring any authentication. The request targets the JSON command parser and due to the lack of proper input validation on the SetCrop parameter, it causes the cgiserver.cgi process to crash, resulting in a device reboot [1]. No user interaction or special network position is required beyond network access to the device.
Impact
Successful exploitation leads to a denial of service as the device reboots. The attacker gains no code execution or data access; the impact is limited to temporary unavailability of the camera functionality (availability impact only). The CVSSv3 score is 8.6 (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H) indicating high severity with network attack vector and no privileges required [1].
Mitigation
As of the publication date (2022-01-28), no patched firmware version has been released for this vulnerability [1]. Users should monitor the vendor's support channels for updates. If the device is exposed to untrusted networks, restrict network access to the camera's web interface as a workaround. The vulnerability is not currently listed in the CISA KEV catalog.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- reolink/RLC-410Wdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- talosintelligence.com/vulnerability_reports/TALOS-2021-1421mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.