cve-2019-11001
HIGH CVSS 7.2 cisa_known_exploited
Description
Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root.
Timeline
- Published
- 2024-12-18
- Last Modified
- 2024-12-18
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cvss": 7.2,
"datePublished": "2024-12-18",
"dateUpdated": "2024-12-18",
"description": "Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the \"TestEmail\" functionality to inject and run OS commands as root.",
"dueDate": "2025-01-08",
"id": "CVE-2019-11001",
"kev_catalogs": [
"cisa"
],
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://reolink.com/product-eol/ ; https://reolink.com/download-center/ ; https://nvd.nist.gov/vuln/detail/CVE-2019-11001",
"product": "Multiple IP Cameras",
"requiredAction": "The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.",
"severity": "HIGH",
"source": "cisa_known_exploited",
"title": "Reolink Multiple IP Cameras OS Command Injection Vulnerability",
"vendor": "Reolink"
}