Umbra Wiki cve cve/CVE-2019-11001
Back to wiki

CVE-2019-11001 — Reolink Multiple IP Cameras OS Command Injection Vulnerability

provenance: imported · CVE: CVE-2019-11001

CVE-2019-11001: Reolink Multiple IP Cameras OS Command Injection Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Reolink
Product Multiple IP Cameras
Date added 2024-12-18
Due date 2025-01-08
Ransomware campaign use Unknown

Description

Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root.

Required action (CISA)

The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

Notes

https://reolink.com/product-eol/ ; https://reolink.com/download-center/ ; https://nvd.nist.gov/vuln/detail/CVE-2019-11001

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2019-11001
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog