VYPR
Unrated severityNVD Advisory· Published Jan 28, 2022· Updated Apr 15, 2025

CVE-2021-44365

CVE-2021-44365

Description

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetDevName param is not object. An attacker can send an HTTP request to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A denial of service vulnerability in reolink RLC-410W cameras allows unauthenticated remote attackers to reboot the device via a crafted HTTP request to the SetDevName parameter in cgiserver.cgi.

Vulnerability

A denial of service vulnerability exists in the JSON command parser functionality of cgiserver.cgi in reolink RLC-410W firmware version v3.0.0.136_20121102. The SetDevName parameter is improperly validated as an object when it is not one, causing the cgiserver.cgi process to crash and trigger a device reboot. No authentication is required to reach this vulnerable code path. [1]

Exploitation

An attacker with network access to the camera can send a specially-crafted HTTP request that supplies a non-object value to the SetDevName parameter. The request does not require any prior authentication or user interaction. The crash of cgiserver.cgi leads to the device rebooting. [1]

Impact

Successful exploitation results in a denial of service condition, causing the camera to reboot and become temporarily unavailable. The reboot primarily affects availability, with no direct impact on confidentiality or integrity. The provided CVSSv3 score is 8.6 (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H), indicating a high-severity impact on availability with changed scope. [1]

Mitigation

As of the publication date (2022-01-28), no patched firmware version has been disclosed in the available references. Users should monitor the vendor's advisory for a fix and restrict network access to the camera's management interface to trusted networks only. [1]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • reolink/RLC-410Wdescription
  • Reolink/RLC-410Wllm-fuzzy
    Range: = v3.0.0.136_20121102

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.