VYPR
Unrated severityNVD Advisory· Published Jan 28, 2022· Updated Apr 15, 2025

CVE-2021-44395

CVE-2021-44395

Description

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetMask param is not object. An attacker can send an HTTP request to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A denial-of-service vulnerability in Reolink RLC-410W cgiserver.cgi allows unauthenticated remote attackers to cause a device reboot via a crafted HTTP request.

Vulnerability

The vulnerability resides in the cgiserver.cgi JSON command parser of the Reolink RLC-410W WiFi security camera, specifically in the handling of the GetMask parameter. Improper input validation (CWE-20) allows an attacker to send a specially-crafted HTTP request that kills the cgiserver.cgi process, triggering a device reboot. The affected firmware version is v3.0.0.136_20121102 [1].

Exploitation

An unauthenticated attacker can exploit this flaw by sending a malicious HTTP request to the camera's web interface. No prior authentication or user interaction is required. The request must include a GetMask parameter that is not an object, causing the JSON parser to fail and crash the process, leading to an immediate reboot [1].

Impact

Successful exploitation results in a denial of service: the camera reboots and becomes temporarily unavailable. There is no impact on confidentiality or integrity; only availability is affected. The CVSSv3 score is 8.6 (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H) [1].

Mitigation

As of the publication date, no official fix or workaround has been disclosed in the available references [1]. Users should monitor vendor advisories for updated firmware and consider network-level access controls to limit exposure until a patch is released.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • reolink/RLC-410Wdescription
  • Reolink/RLC-410Wllm-fuzzy
    Range: = v3.0.0.136_20121102

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.