VYPR
Unrated severityNVD Advisory· Published Jan 28, 2022· Updated Apr 15, 2025

CVE-2021-44409

CVE-2021-44409

Description

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. TestWifi param is not object. An attacker can send an HTTP request to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A denial of service vulnerability in Reolink RLC-410W's cgiserver.cgi allows unauthenticated remote attackers to reboot the device via a crafted HTTP request.

Vulnerability

The vulnerability exists in the cgiserver.cgi JSON command parser of Reolink RLC-410W firmware version v3.0.0.136_20121102. The TestWifi parameter is not validated as an object, leading to improper input validation (CWE-20). A specially-crafted HTTP request can cause the cgiserver.cgi process to terminate, resulting in a device reboot. [1]

Exploitation

An attacker can send an HTTP request to the camera's web interface without requiring authentication. The request must include a malformed JSON payload where the TestWifi parameter is not an object. This triggers the parsing flaw, causing the process to crash and the device to reboot. [1]

Impact

Successful exploitation results in a denial of service (DoS) condition, causing the camera to reboot and become temporarily unavailable. The impact is limited to availability; no data confidentiality or integrity is compromised. The CVSS v3 score is 8.6 (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H). [1]

Mitigation

As of the advisory publication date (2022-01-28), no official patch has been released by Reolink. Users should monitor vendor updates for a firmware fix. Until a patch is available, consider restricting network access to the camera's web interface to trusted hosts only. [1]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • reolink/RLC-410Wdescription
  • Reolink/RLC-410Wllm-fuzzy
    Range: = 3.0.0.136_20121102

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.