ID

VAR-201806-1895


TITLE

Reolink Camera Remote Command Execution Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2018-11079

DESCRIPTION

Shenzhen Ruilian Digital Technology Co., Ltd. is committed to developing leading Internet video products and video content services, providing cameras for security, sports, entertainment, nursing and other subdivision applications for the consumer market, and providing live broadcast, video sharing and Content services such as video cloud storage. Its Reolink brand enjoys high visibility and market share in video products in Europe and the United States. There is a remote command execution vulnerability in the Reolink camera. This vulnerability is caused by a command injection in a form in the advanced web settings function of the web management system of the camera. At the same time, some cameras in the network space use the default password, and the attacker can use the vulnerability to remotely execute arbitrary. command.

Trust: 0.6

sources: CNVD: CNVD-2018-11079

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-11079

AFFECTED PRODUCTS

vendor:reolinkmodel:rlc-423 1288 18020711scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2018-11079

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2018-11079
value: HIGH

Trust: 0.6

CNVD: CNVD-2018-11079
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2018-11079

PATCH

title:Reolink camera remote command execution vulnerability patchurl:https://www.cnvd.org.cn/patchinfo/show/131493

Trust: 0.6

sources: CNVD: CNVD-2018-11079

EXTERNAL IDS

db:CNVDid:CNVD-2018-11079

Trust: 0.6

sources: CNVD: CNVD-2018-11079

REFERENCES

url:https://github.com/mcw0/poc/blob/master/reolink-ipc-rce.py

Trust: 0.6

sources: CNVD: CNVD-2018-11079

SOURCES

db:CNVDid:CNVD-2018-11079

LAST UPDATE DATE

2022-05-04T09:47:13.083000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-11079date:2018-06-08T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-11079date:2018-06-07T00:00:00