VYPR
Unrated severityNVD Advisory· Published Jan 28, 2022· Updated Apr 15, 2025

CVE-2021-44371

CVE-2021-44371

Description

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetEmail param is not object. An attacker can send an HTTP request to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A DoS vulnerability in Reolink RLC-410W cameras allows unauthenticated remote attackers to trigger a reboot via a crafted HTTP request to the cgiserver.cgi JSON parser.

Vulnerability

The vulnerability resides in the JSON command parser of the cgiserver.cgi component on Reolink RLC-410W cameras running firmware version v3.0.0.136_20121102. Specifically, when parsing the SetEmail parameter, the parser does not validate that the parameter is an object, leading to improper input validation (CWE-20) [1]. This allows an unauthenticated attacker to cause a denial of service.

Exploitation

An attacker can exploit this vulnerability by sending a crafted HTTP request to the camera's web server. No authentication is required. The request must include a malformed SetEmail parameter that is not an object, triggering the parser to crash the cgiserver.cgi process and resulting in a reboot of the device [1].

Impact

Successful exploitation causes the device to reboot, temporarily disrupting surveillance functions. The impact is a denial of service (CIA: availability) with high severity (CVSSv3 8.6) and no impact on confidentiality or integrity [1].

Mitigation

As of the publication date (2022-01-28), no fix was available from Reolink. Users should monitor for firmware updates that address this vulnerability. The device may be listed in vendor advisories; however, the Talos report indicates a large number of similar CVEs [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • reolink/RLC-410Wdescription
  • Reolink/RLC-410Wllm-fuzzy
    Range: = v3.0.0.136_20121102

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.