VYPR
Unrated severityNVD Advisory· Published Jan 28, 2022· Updated Apr 15, 2025

CVE-2021-44389

CVE-2021-44389

Description

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetAbility param is not object. An attacker can send an HTTP request to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated HTTP request to the cgiserver.cgi JSON parser can crash the process, forcing a reboot of the Reolink RLC-410W camera (firmware v3.0.0.136_20121102).

Vulnerability

The cgiserver.cgi JSON command parser in Reolink RLC-410W firmware version v3.0.0.136_20121102 does not properly validate the GetAbility parameter when it is not an object. A specially-crafted HTTP POST request can trigger a crash of the cgiserver.cgi process, leading to an immediate device reboot. No authentication is required to exploit this flaw [1].

Exploitation

An unauthenticated attacker with network access to the camera can send a crafted HTTP request containing a malicious JSON payload where the GetAbility parameter is not set to an object. The crash of cgiserver.cgi occurs upon parsing this malformed parameter, causing the device to reboot without any user interaction [1].

Impact

Successful exploitation results in a denial of service (DoS) condition by forcing the camera to reboot, interrupting its video recording and monitoring functions. The CVSS v3.0 base score is 8.6, with a high availability impact; no impact on confidentiality or integrity [1].

Mitigation

As of the publication date (January 28, 2022), no patched firmware version has been released by Reolink for this vulnerability. The affected firmware is v3.0.0.136_20121102. Users may consider restricting network access to the camera or deploying additional firewall rules to block unauthenticated requests to the vulnerable endpoint until a fix becomes available [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • reolink/RLC-410Wdescription
  • Reolink/RLC-410Wllm-fuzzy
    Range: = v3.0.0.136_20121102

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.