CVE-2021-44366
Description
Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A remote unauthenticated attacker can send a specially-crafted HTTP request to the cgiserver.cgi JSON command parser, causing a reboot of the Reolink RLC-410W camera.
Vulnerability
Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W firmware version v3.0.0.136_20121102. A specially-crafted HTTP request that exploits an improper input validation (CWE-20) can lead to killing the cgiserver.cgi process, triggering a device reboot [1].
Exploitation
An attacker can send an HTTP request to the camera without requiring any authentication, prior network access, or user interaction. The request targets the cgiserver.cgi endpoint and contains a malformed JSON payload that is not properly validated, causing the process to terminate [1].
Impact
Successful exploitation results in a denial of service condition, forcing the camera to reboot. This disrupts the device's normal operation, including video recording and network accessibility, until the reboot completes. The impact is limited to availability; no data integrity or confidentiality breaches have been reported [1].
Mitigation
As of the publication date (2022-04-14), no firmware update or vendor-supplied fix is available in the references. Users should monitor the vendor for patches and consider network segmentation or firewall rules to limit exposure of the device's management interface to untrusted networks [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- talosintelligence.com/vulnerability_reports/TALOS-2021-1421mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.