peter bassill · operator
$ cve CVE-2019-11001 JSON

CVE-2019-11001 KEV

7.2
HIGH · CVSS 3.1 · EPSS 37.5% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2025-01-08.

Description

On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.

Scoring

CVSS7.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS37.54% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2025-01-08
Public exploitnone known
Published2019-04-08
Last modified2026-06-17

CISA KEV

NameReolink Multiple IP Cameras OS Command Injection Vulnerability
Added2024-12-18
Due2025-01-08
Vendor / productReolink / Multiple IP Cameras
Ransomware usenone reported

Affected (10)

VendorProduct
reolinkc1 pro
reolinkc1 pro firmware
reolinkc2 pro
reolinkc2 pro firmware
reolinkrlc-410w
reolinkrlc-410w firmware
reolinkrlc-422w
reolinkrlc-422w firmware
reolinkrlc-511w
reolinkrlc-511w firmware

References

→ the Explorer  ·  watch your stack  ·  NVD