peter bassill · operator
$ cve CVE-2021-40407 JSON

CVE-2021-40407 KEV

7.2
HIGH · CVSS 3.1 · EPSS 47.6% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2025-01-08.

Description

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->domain variable, that has the value of the domain parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection. An attacker can send an HTTP request to trigger this vulnerability.

Scoring

CVSS7.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS47.64% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2025-01-08
Public exploitnone known
Published2022-01-28
Last modified2026-06-17

CISA KEV

NameReolink RLC-410W IP Camera OS Command Injection Vulnerability
Added2024-12-18
Due2025-01-08
Vendor / productReolink / RLC-410W IP Camera
Ransomware usenone reported

Affected (2)

VendorProduct
reolinkrlc-410w
reolinkrlc-410w firmware

References

→ the Explorer  ·  watch your stack  ·  NVD