cve-2021-40407
CRITICAL CVSS 9.1 cisa_known_exploited
Description
Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.
Timeline
- Published
- 2024-12-18
- Last Modified
- 2024-12-18
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cvss": 9.1,
"datePublished": "2024-12-18",
"dateUpdated": "2024-12-18",
"description": "Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.",
"dueDate": "2025-01-08",
"id": "CVE-2021-40407",
"kev_catalogs": [
"cisa"
],
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://reolink.com/product-eol/ ; https://reolink.com/download-center/ ; https://nvd.nist.gov/vuln/detail/CVE-2021-40407",
"product": "RLC-410W IP Camera",
"requiredAction": "The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.",
"severity": "CRITICAL",
"source": "cisa_known_exploited",
"title": "Reolink RLC-410W IP Camera OS Command Injection Vulnerability ",
"vendor": "Reolink"
}