VYPR
Unrated severityNVD Advisory· Published Jan 28, 2022· Updated Apr 15, 2025

CVE-2021-44376

CVE-2021-44376

Description

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetIsp param is not object. An attacker can send an HTTP request to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A DoS vulnerability in Reolink RLC-410W cgiserver.cgi allows an unauthenticated attacker to reboot the device via a crafted HTTP request.

Vulnerability

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser of the Reolink RLC-410W wireless security camera running firmware version v3.0.0.136_20121102. The SetIsp parameter is not validated as an object, allowing a specially crafted HTTP request to trigger a reboot of the device. This affects the JSON command parser functionality which is reachable without authentication [1].

Exploitation

An attacker can exploit this vulnerability by sending a malicious HTTP request to the camera's cgiserver.cgi endpoint with a malformed SetIsp parameter that is not an object. No authentication is required and the attack can be performed over the network. The request causes the cgiserver.cgi process to crash, leading to an immediate reboot of the device [1].

Impact

Successful exploitation results in a denial of service condition, causing the camera to reboot and become temporarily unavailable. This can interrupt surveillance operations and require manual intervention if the device fails to recover properly. No data confidentiality or integrity impact is expected, but the availability impact is high as the device becomes non-functional during the reboot cycle [1].

Mitigation

As of the publication date, no fixed firmware version has been released by Reolink. Users should monitor the vendor's support site for future updates. Until a patch is available, restricting network access to the camera's web interface and placing the device behind a firewall can help reduce the attack surface. The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • reolink/RLC-410Wdescription
  • Reolink/RLC-410Wllm-fuzzy
    Range: = v3.0.0.136_20121102

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.