PT-2021-7510 · Reolink · Reolink Rlc-410W Ip Camera

Francesco Benvenuto

·

Published

2021-12-06

·

Updated

2025-04-02

·

CVE-2021-40407

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Reolink RLC-410W IP Camera version 3.0.0.136 20121102
Description An OS command injection vulnerability exists in the device network settings functionality due to improper validation of the ddns->domain variable. This variable has the value of the domain parameter provided through the SetDdns API. An attacker can send an HTTP request to trigger this vulnerability, potentially allowing remote execution of arbitrary commands. The issue is related to the DDNS type and the domain parameter.
Recommendations For Reolink RLC-410W IP Camera version 3.0.0.136 20121102, as a temporary workaround, consider disabling the SetDdns API or restricting access to it until a patch is available. Additionally, avoid using the domain parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2022-07053
CVE-2021-40407

Affected Products

Reolink Rlc-410W Ip Camera