VYPR

RLC-410W

by Reolink

CVEs (88)

  • CVE-2021-40406HigJan 28, 2022
    risk 0.49cvss 7.5epss 0.02

    A denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to prevent users from logging in. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2021-40411HigJan 28, 2022
    risk 0.47cvss 7.2epss 0.05

    An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [6] the dns_data->dns2 variable, that has the value of the dns2 parameter provided through the SetLocalLink API, is not validated properly. This…

  • CVE-2021-40414HigJan 28, 2022
    risk 0.46cvss 7.1epss 0.01

    An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The SetMdAlarm API sets the movement detection parameters, giving the ability to set the sensitivity of the camera per a range of…

  • CVE-2021-40413HigJan 28, 2022
    risk 0.46cvss 7.1epss 0.01

    An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The UpgradePrepare is the API that checks if a provided filename identifies a new version of the RLC-410W firmware. If the version…

  • CVE-2021-40405MedApr 14, 2022
    risk 0.42cvss 6.5epss 0.01

    A denial of service vulnerability exists in the cgiserver.cgi Upgrade API functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2021-40415MedJan 28, 2022
    risk 0.42cvss 6.5epss 0.01

    An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. In cgi_check_ability the Format API does not have a specific case, the user permission will default to 7. This will give…

  • CVE-2021-40404MedJan 28, 2022
    risk 0.42cvss 6.5epss 0.01

    An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to authentication bypass. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-21199MedJan 28, 2022
    risk 0.38cvss 5.9epss 0.01

    An information disclosure vulnerability exists due to the hardcoded TLS key of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information. An attacker can perform a man-in-the-middle attack to trigger this…

Page 5 of 5