VYPR
Unrated severityNVD Advisory· Published Apr 14, 2022· Updated Apr 15, 2025

CVE-2021-44366

CVE-2021-44366

Description

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A remote unauthenticated attacker can send a specially-crafted HTTP request to the cgiserver.cgi JSON command parser, causing a reboot of the Reolink RLC-410W camera.

Vulnerability

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W firmware version v3.0.0.136_20121102. A specially-crafted HTTP request that exploits an improper input validation (CWE-20) can lead to killing the cgiserver.cgi process, triggering a device reboot [1].

Exploitation

An attacker can send an HTTP request to the camera without requiring any authentication, prior network access, or user interaction. The request targets the cgiserver.cgi endpoint and contains a malformed JSON payload that is not properly validated, causing the process to terminate [1].

Impact

Successful exploitation results in a denial of service condition, forcing the camera to reboot. This disrupts the device's normal operation, including video recording and network accessibility, until the reboot completes. The impact is limited to availability; no data integrity or confidentiality breaches have been reported [1].

Mitigation

As of the publication date (2022-04-14), no firmware update or vendor-supplied fix is available in the references. Users should monitor the vendor for patches and consider network segmentation or firewall rules to limit exposure of the device's management interface to untrusted networks [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Reolink/RLC-410Wllm-fuzzy2 versions
    = 3.0.0.136_20121102+ 1 more
    • (no CPE)range: = 3.0.0.136_20121102
    • (no CPE)range: v3.0.0.136_20121102

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.