HIGH🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2019-11001

CVSS 7.2v3.1pub. 2019-04-08upd. 2025-11-06

On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Reolink C1 Pro

    HW
    Reolink
    all versions
  • Reolink C1 Pro Firmware

    OS
    Reolink
    ≤ 1.0.227
  • Reolink C2 Pro

    HW
    Reolink
    all versions
  • Reolink C2 Pro Firmware

    OS
    Reolink
    ≤ 1.0.227
  • Reolink Rlc 410w

    HW
    Reolink
    all versions
  • Reolink Rlc 410w Firmware

    OS
    Reolink
    ≤ 1.0.227
  • Reolink Rlc 422w

    HW
    Reolink
    all versions
  • Reolink Rlc 422w Firmware

    OS
    Reolink
    ≤ 1.0.227
  • Reolink Rlc 511w

    HW
    Reolink
    all versions
  • Reolink Rlc 511w Firmware

    OS
    Reolink
    ≤ 1.0.227

CISA KEV — detailsi

Vendori
Reolink
Producti
Multiple IP Cameras
Added to KEVi
December 18, 2024
Remediation deadline (US Federal)i
January 8, 2025(overdue)
Required action (CISA)i

The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

CISA descriptioni

Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 8 stycznia 2025
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2021-40408CRITICAL9.8PL ✓same product

Command injection w ustawieniach sieciowych Reolink RLC-410W

CVE-2022-21217CRITICAL9.8PL ✓same product

Out-of-bounds write w funkcji TestEmail kamery Reolink RLC-410W

CVE-2021-40409CRITICAL9.8PL ✓same product

Command injection w ustawieniach sieciowych Reolink RLC-410W

CVE-2021-40407HIGH7.2⚠ KEVsame product

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W ...

CVE-2021-44354HIGH7.5same product

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reo...