← All CVEs

CVE-2019-11001

high · 7.2Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

Added 2024-12-18Remediation due 2025-01-08

On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.

7.2
CVSS
37.5%
EPSS (exploit prob.)
98th
EPSS percentile
2019-04-08
Published

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
reolinkrlc-410w_firmware<= 1.0.227
reolinkrlc-410wall versions
reolinkc1_pro_firmware<= 1.0.227
reolinkc1_proall versions
reolinkc2_pro_firmware<= 1.0.227
reolinkc2_proall versions
reolinkrlc-422w_firmware<= 1.0.227
reolinkrlc-422wall versions
reolinkrlc-511w_firmware<= 1.0.227
reolinkrlc-511wall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-11001