CVE-2019-11001
high · 7.2Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
Added 2024-12-18Remediation due 2025-01-08
On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.
7.2
CVSS
37.5%
EPSS (exploit prob.)
98th
EPSS percentile
2019-04-08
Published
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| reolink | rlc-410w_firmware | <= 1.0.227 |
| reolink | rlc-410w | all versions |
| reolink | c1_pro_firmware | <= 1.0.227 |
| reolink | c1_pro | all versions |
| reolink | c2_pro_firmware | <= 1.0.227 |
| reolink | c2_pro | all versions |
| reolink | rlc-422w_firmware | <= 1.0.227 |
| reolink | rlc-422w | all versions |
| reolink | rlc-511w_firmware | <= 1.0.227 |
| reolink | rlc-511w | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/mcw0/PoC/blob/master/Reolink-IPC-RCE.py
- https://www.vdoo.com/blog/working-with-the-community-%E2%80%93-significant-vulnerabilities-in-reolink-cameras/
- https://github.com/mcw0/PoC/blob/master/Reolink-IPC-RCE.py
- https://www.vdoo.com/blog/working-with-the-community-%E2%80%93-significant-vulnerabilities-in-reolink-cameras/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11001
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-11001