VYPR

Desktop Application

by Reolink

CVEs (4)

  • CVE-2025-56799MedOct 21, 2025
    risk 0.42cvss 6.5epss 0.01

    Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted folder name. NOTE: this is disputed by the Supplier because a crafted folder name would arise only if the local user were attacking himself.

  • CVE-2025-56802MedOct 21, 2025
    risk 0.33cvss 5.1epss 0.00

    The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files allowing attackers with local access to decrypt sensitive application data stored in %APPDATA%. A different vulnerability than CVE-2025-56801. NOTE: the…

  • CVE-2025-56801MedOct 21, 2025
    risk 0.33cvss 5.1epss 0.00

    The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data. NOTE: the Supplier's…

  • CVE-2025-56800MedOct 21, 2025
    risk 0.33cvss 5.1epss 0.00

    Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application implements lock screen password logic entirely on the client side using JavaScript within an Electron resource file. Because the password is stored and returned…