VYPR
Unrated severityNVD Advisory· Published Jan 28, 2022· Updated Apr 15, 2025

CVE-2021-44414

CVE-2021-44414

Description

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. DelUser param is not object. An attacker can send an HTTP request to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reolink RLC-410W camera firmware v3.0.0.136_20121102 has a DoS vulnerability in the JSON command parser of cgiserver.cgi that can be triggered by a crafted HTTP request causing a reboot.

Vulnerability

The denial of service vulnerability exists in the JSON command parser functionality of cgiserver.cgi on Reolink RLC-410W running firmware version 3.0.0.136_20121102. Specifically, the DelUser parameter is expected to be an object but is not properly validated, leading to a crash of the cgiserver.cgi process and subsequent device reboot. Affected firmware version is v3.0.0.136_20121102 [1].

Exploitation

An attacker can exploit this vulnerability by sending a specially-crafted HTTP request to the camera's web interface. No authentication is required, and the attack can be performed over the network. The attacker does not need any special privileges or user interaction [1].

Impact

Successful exploitation causes the cgiserver.cgi process to be killed, resulting in immediate reboot of the device. This constitutes a denial of service (DoS) condition, as the camera becomes unavailable temporarily. The CIA impact is: availability only, with no confidentiality or integrity impact. The CVSSv3 score is 8.6 (High) with vector AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H [1].

Mitigation

As of the publication date (2022-01-28), Reolink has not released a firmware update addressing this vulnerability. Users should monitor vendor advisories for patches. No workaround is described in the available references [1]. If a fix becomes available, it should be applied immediately to mitigate the risk.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • reolink/RLC-410Wdescription
  • Reolink/RLC-410Wllm-fuzzy
    Range: =3.0.0.136_20121102

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.