Executive brief
Multiple Reolink IP cameras contain an authenticated OS command injection vulnerability in the TestEmail functionality. An attacker with administrative privileges can execute arbitrary commands as root by injecting shell metacharacters into the addr1 field.
Affected products
- Reolink RLC-410W firmware through 1.0.227
- Reolink C1 Pro firmware through 1.0.227
- Reolink C2 Pro firmware through 1.0.227
- Reolink RLC-422W firmware through 1.0.227
- Reolink RLC-511W firmware through 1.0.227
Timeline
- 2024-12-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-12-18: disclosed