Medium severity5.3NVD Advisory· Published Oct 22, 2024· Updated Apr 15, 2026
CVE-2024-48644
CVE-2024-48644
Description
Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_23031701) allows remote attackers to determine valid user accounts via login attempts. This can lead to the enumeration of user accounts and potentially facilitate other attacks, such as brute-forcing of passwords. The vulnerability arises from the application responding differently to login attempts with valid and invalid usernames.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: = 3.0.0.1889_23031701
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.