Executive brief
A security vulnerability in the Reolink Home Hub, a central management device for smart security cameras, could allow an attacker on the same local network to gain unauthorized access to connected cameras. By exploiting weak credential protections in the hub's internal services, an attacker could intercept video traffic or compromise camera login details. This could lead to a significant breach of privacy and unauthorized monitoring of the protected premises.
Technical details
A vulnerability classified as Use of Weak Credentials (CWE-1391) exists in the netclient and factory services of the Reolink Home Hub. The flaw allows an unauthenticated attacker located on the same adjacent network (LAN) to perform brute-force attacks against device credentials. Successful exploitation enables the attacker to intercept communication between the Hub and its associated cameras, leading to the compromise of camera credentials and potential unauthorized access to video streams. The issue is addressed in firmware versions v3.3.0.456_26031911 and later.
Affected products
- Reolink Home Hub prior to v3.3.0.456_26031911
Timeline
- 2026-06-26: advisory: Advisory published by Nozomi Networks and NVD
- 2026-06-26: disclosed