CVE-2019-11001
גבוהה 7.2 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Reolink Multiple IP Cameras OS Command Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
תיאור (מקור, אנגלית)
On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.
מדדים
- CVSS 3.1
-
7.2 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 38% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-78
מוצרים מושפעים
reolink: rlc-410w firmware; reolink: rlc-410w; reolink: c1 pro firmware; reolink: c1 pro; reolink: c2 pro firmware; reolink: c2 pro; reolink: rlc-422w firmware; reolink: rlc-422w; reolink: rlc-511w firmware; reolink: rlc-511w
קישורים
- https://github.com/mcw0/PoC/blob/master/Reolink-IPC-RCE.py ExploitThird Party Advisory
- https://www.vdoo.com/blog/working-with-the-community-%E2%80%93-significant-vul… Broken LinkExploitThird Party Advisory
- https://github.com/mcw0/PoC/blob/master/Reolink-IPC-RCE.py ExploitThird Party Advisory
- https://www.vdoo.com/blog/working-with-the-community-%E2%80%93-significant-vul… Broken LinkExploitThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource