VYPR
Unrated severityNVD Advisory· Published Jan 28, 2022· Updated Apr 15, 2025

CVE-2021-44410

CVE-2021-44410

Description

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. UpgradePrepare param is not object. An attacker can send an HTTP request to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A denial of service vulnerability in Reolink RLC-410W camera's cgiserver.cgi allows unauthenticated remote attackers to trigger a device reboot via a specially crafted HTTP request.

Vulnerability

The vulnerability exists in the cgiserver.cgi JSON command parser of Reolink RLC-410W firmware version v3.0.0.136_20121102. A specially-crafted HTTP request where the UpgradePrepare parameter is not an object can cause the cgiserver.cgi process to terminate, leading to a device reboot. This issue is classified as CWE-20 (Improper Input Validation) [1].

Exploitation

An attacker can send an HTTP request to the device without requiring any authentication or user interaction. The attack is network-based, over the LAN or WAN if the device is exposed. By crafting the request so that the UpgradePrepare JSON parameter is not an object (e.g., a string or number) instead of the expected object type, the parser enters an error state that kills the process [1].

Impact

Successful exploitation causes the cgiserver.cgi process to terminate, which triggers an immediate reboot of the device. This results in a denial of service (availability impact). The CVSSv3 score is 8.6 (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H), indicating high severity with no confidentiality or integrity impact [1].

Mitigation

As of the available reference, no patched firmware version has been released. Reolink has been notified but the timeline for a fix is unknown. Users should consider network-level protections, such as restricting HTTP access to the camera from trusted networks only, until an update is provided [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • reolink/RLC-410Wdescription
  • Reolink/RLC-410Wllm-fuzzy
    Range: = 3.0.0.136_20121102

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.