SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2019-11001

Reolink Multiple IP Cameras OS Command Injection Vulnerability

KEVHIGH 7.2EPSS 37.5%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 8 January 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
37.54% probability · 98th percentile
CISA KEV
Listed 18 December 2024 · due 8 January 2025
Weakness
CWE-78
Affected
reolink/rlc-410w firmware · reolink/c1 pro firmware · reolink/c2 pro firmware · reolink/rlc-422w firmware · reolink/rlc-511w firmware
Source
cve@mitre.org

CISA notes

The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable. https://reolink.com/product-eol/ ; https://reolink.com/download-center/ ; https://nvd.nist.gov/vuln/detail/CVE-2019-11001

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.