ID

VAR-201901-1690


TITLE

Reolink camera has multiple vulnerabilities

Trust: 0.6

sources: CNVD: CNVD-2019-01876

DESCRIPTION

Shenzhen Ruilian Digital Technology Co., Ltd. is committed to developing leading Internet video products and video content services, providing cameras for security, sports, entertainment, nursing and other subdivision applications for the consumer market, and providing live broadcast, video sharing and Content services such as video cloud storage. The Reolink camera has a remote command execution vulnerability and two unauthorized stack overflow vulnerabilities. An attacker could use a remote command execution vulnerability in conjunction with the default credentials admin: empty or weak passwords to bypass the authentication limit and remotely take over the camera.

Trust: 0.6

sources: CNVD: CNVD-2019-01876

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-01876

AFFECTED PRODUCTS

vendor:reolinkmodel:rlc-423scope: - version: -

Trust: 0.6

vendor:reolinkmodel:rlc 410scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2019-01876

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2019-01876
value: HIGH

Trust: 0.6

CNVD: CNVD-2019-01876
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2019-01876

EXTERNAL IDS

db:CNVDid:CNVD-2019-01876

Trust: 0.6

sources: CNVD: CNVD-2019-01876

REFERENCES

url:https://github.com/mcw0/poc/blob/master/reolink-ipc-rce.py

Trust: 0.6

sources: CNVD: CNVD-2019-01876

SOURCES

db:CNVDid:CNVD-2019-01876

LAST UPDATE DATE

2022-05-04T09:50:54.069000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-01876date:2019-01-17T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-01876date:2019-01-17T00:00:00