Junglewise Threat Intelligence

CVE-2021-40407: Reolink RLC-410W IP Camera OS Command Injection Vulnerability

CVE-2021-40407 · Severity: critical · CVSS 9.1 · Exploited in the wild · Published 2024-12-18

Executive brief

An OS command injection vulnerability exists in the Reolink RLC-410W IP camera due to improper validation of the domain parameter in the SetDdns API. An authenticated attacker can trigger this vulnerability by sending a specially crafted HTTP request to the device's network settings functionality, leading to arbitrary command execution.

Affected products

  • Reolink RLC-410W Firmware 3.0.0.136_20121102
  • Reolink RLC-410W IP Camera

Timeline

  • 2022-01-28: disclosed: NVD Published Date
  • 2024-12-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog