VYPR
Unrated severityNVD Advisory· Published Aug 22, 2025· Updated Sep 4, 2025

CVE-2025-55621

CVE-2025-55621

Description

An Insecure Direct Object Reference (IDOR) vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access and download other users' profile photos via a crafted URL. NOTE: this is disputed by the Supplier because it is intentional behavior; the photos are part of a social platform on which users expect to find one another.

Affected products

2
  • Reolink/Reolinkdescription
  • Reolink/Reolinkllm-fuzzy
    Range: = 4.54.0.4.20250526

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.