CVE-2021-40407 KEV
7.2
HIGH · CVSS 3.1 · EPSS 47.6% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2025-01-08.
Description
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->domain variable, that has the value of the domain parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection. An attacker can send an HTTP request to trigger this vulnerability.
Scoring
| CVSS | 7.2 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 47.64% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | yes — remediate by 2025-01-08 |
| Public exploit | none known |
| Published | 2022-01-28 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Reolink RLC-410W IP Camera OS Command Injection Vulnerability |
|---|---|
| Added | 2024-12-18 |
| Due | 2025-01-08 |
| Vendor / product | Reolink / RLC-410W IP Camera |
| Ransomware use | none reported |
Affected (2)
| Vendor | Product |
|---|---|
| reolink | rlc-410w |
| reolink | rlc-410w firmware |
References
→ the Explorer · watch your stack · NVD