← לוח פגיעויות

CVE-2019-11001

גבוהה 7.2 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Reolink Multiple IP Cameras OS Command Injection Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

תיאור (מקור, אנגלית)

On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.

מדדים

CVSS 3.1
7.2 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
38% (אחוזון 100) נכון ל-30/7/2026
CWE
CWE-78

מוצרים מושפעים

reolink: rlc-410w firmware; reolink: rlc-410w; reolink: c1 pro firmware; reolink: c1 pro; reolink: c2 pro firmware; reolink: c2 pro; reolink: rlc-422w firmware; reolink: rlc-422w; reolink: rlc-511w firmware; reolink: rlc-511w

קישורים