CVE-2021-40407 — Reolink RLC-410W IP Camera OS Command Injection Vulnerability
CVE-2021-40407: Reolink RLC-410W IP Camera OS Command Injection Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Reolink |
| Product | RLC-410W IP Camera |
| Date added | 2024-12-18 |
| Due date | 2025-01-08 |
| Ransomware campaign use | Unknown |
Description
Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.
Required action (CISA)
The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
Notes
https://reolink.com/product-eol/ ; https://reolink.com/download-center/ ; https://nvd.nist.gov/vuln/detail/CVE-2021-40407
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2021-40407
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog