CVE-2021-44414
Description
A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. DelUser param is not object. An attacker can send an HTTP request to trigger this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Reolink RLC-410W camera firmware v3.0.0.136_20121102 has a DoS vulnerability in the JSON command parser of cgiserver.cgi that can be triggered by a crafted HTTP request causing a reboot.
Vulnerability
The denial of service vulnerability exists in the JSON command parser functionality of cgiserver.cgi on Reolink RLC-410W running firmware version 3.0.0.136_20121102. Specifically, the DelUser parameter is expected to be an object but is not properly validated, leading to a crash of the cgiserver.cgi process and subsequent device reboot. Affected firmware version is v3.0.0.136_20121102 [1].
Exploitation
An attacker can exploit this vulnerability by sending a specially-crafted HTTP request to the camera's web interface. No authentication is required, and the attack can be performed over the network. The attacker does not need any special privileges or user interaction [1].
Impact
Successful exploitation causes the cgiserver.cgi process to be killed, resulting in immediate reboot of the device. This constitutes a denial of service (DoS) condition, as the camera becomes unavailable temporarily. The CIA impact is: availability only, with no confidentiality or integrity impact. The CVSSv3 score is 8.6 (High) with vector AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H [1].
Mitigation
As of the publication date (2022-01-28), Reolink has not released a firmware update addressing this vulnerability. Users should monitor vendor advisories for patches. No workaround is described in the available references [1]. If a fix becomes available, it should be applied immediately to mitigate the risk.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- reolink/RLC-410Wdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- talosintelligence.com/vulnerability_reports/TALOS-2021-1421mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.