CVE-2021-40408
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns-username variable, that has the value of the userName parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection.
CRITICAL · CVSS 9.8
EPSS 0.01559
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0