CVE-2019-11001
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root.
CISA KEV
- Vendor
- Reolink
- Product
- Multiple IP Cameras
- Due date
- 2025-01-08
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://reolink.com/product-eol/ ; https://reolink.com/download-center/ ; https://nvd.nist.gov/vuln/detail/CVE-2019-11001
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.