CVE-2019-11001

unknown KEV
Published 2024-12-18 · Modified 2024-12-18
CVSS v3
CVSS v2
VIR risk
1.5

Description

Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root.

CISA KEV

Vendor
Reolink
Product
Multiple IP Cameras
Due date
2025-01-08

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://reolink.com/product-eol/ ; https://reolink.com/download-center/ ; https://nvd.nist.gov/vuln/detail/CVE-2019-11001

Exploits

References

Verify integrity in audit chain (admin only). AS-IS.