Junglewise Threat Intelligence

CVE-2019-11001: Reolink Multiple IP Cameras OS Command Injection Vulnerability

CVE-2019-11001 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2024-12-18

Executive brief

Multiple Reolink IP cameras contain an authenticated OS command injection vulnerability in the TestEmail functionality. An attacker with administrative privileges can execute arbitrary commands as root by injecting shell metacharacters into the addr1 field.

Affected products

  • Reolink RLC-410W firmware through 1.0.227
  • Reolink C1 Pro firmware through 1.0.227
  • Reolink C2 Pro firmware through 1.0.227
  • Reolink RLC-422W firmware through 1.0.227
  • Reolink RLC-511W firmware through 1.0.227

Timeline

  • 2024-12-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-12-18: disclosed