VYPR
Unrated severityNVD Advisory· Published Jan 28, 2022· Updated Apr 15, 2025

CVE-2021-44397

CVE-2021-44397

Description

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. rtmp=start param is not object. An attacker can send an HTTP request to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A denial-of-service vulnerability in Reolink RLC-410W's cgiserver.cgi JSON parser allows unauthenticated remote attackers to trigger a device reboot via a crafted HTTP request.

Vulnerability

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W firmware version 3.0.0.136_20121102. The parser fails to properly validate the rtmp=start parameter when it is not an object, leading to a crash of the cgiserver.cgi process. The vulnerability is classified as CWE-20 (Improper Input Validation) [1].

Exploitation

An attacker can exploit this vulnerability by sending a specially-crafted HTTP request to the camera's web interface. No authentication is required, and the attacker does not need any prior knowledge of the device beyond network access. The crafted request causes the cgiserver.cgi process to terminate, resulting in a system reboot [1].

Impact

Successful exploitation leads to a denial of service condition where the device becomes unresponsive and reboots. This disrupts the camera's surveillance functionality until the reboot completes. The impact is limited to availability; no data confidentiality or integrity is compromised [1].

Mitigation

As of the publication date, no firmware update fixing this vulnerability has been released for the Reolink RLC-410W. Users should monitor the vendor's support channels for updates and consider network-level access controls (e.g., firewall rules) to restrict exposure of the camera's web interface to trusted networks only. The device is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of this writing [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • reolink/RLC-410Wdescription
  • Reolink/RLC-410Wllm-fuzzy
    Range: = v3.0.0.136_20121102 firmware

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.