VYPR
Unrated severityNVD Advisory· Published Jan 28, 2022· Updated Apr 15, 2025

CVE-2021-44391

CVE-2021-44391

Description

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetEnc param is not object. An attacker can send an HTTP request to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A denial of service vulnerability in reolink RLC-410W's cgiserver.cgi allows unauthenticated remote attackers to cause a device reboot via a specially crafted HTTP request.

Vulnerability

The vulnerability resides in the JSON command parser of cgiserver.cgi in reolink RLC-410W firmware version v3.0.0.136_20121102. The GetEnc parameter is not validated as an object, allowing a specially crafted HTTP request to trigger a denial of service condition that kills the cgiserver.cgi process and causes the device to reboot. [1]

Exploitation

An unauthenticated attacker can send a crafted HTTP request to the device's web interface. No authentication or user interaction is required. The request exploits improper input validation (CWE-20) in the JSON parser, specifically when handling the GetEnc parameter. The attack is network-based and can be executed remotely. [1]

Impact

Successful exploitation results in a denial of service, causing the device to reboot. This disrupts the camera's functionality, including video streaming and recording, until the device completes its reboot cycle. The impact is limited to availability; no data confidentiality or integrity is compromised. [1]

Mitigation

As of the publication date (2022-01-28), no official patch has been released by reolink. Users should monitor vendor advisories for firmware updates. As a workaround, restrict network access to the camera's web interface to trusted networks only. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. [1]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • reolink/RLC-410Wdescription
  • Reolink/RLC-410Wllm-fuzzy
    Range: = 3.0.0.136_20121102

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.