ZeroHour

CVE-2019-11001

KEV PoC ×2mass

Authenticated OS Command Injection in Reolink IP Cameras (CVE-2019-11001)

CISA: Reolink Multiple IP Cameras OS Command Injection Vulnerability

CVSS 3.1
7.2 high
EPSS
38%p98
Published
()
KEV added
AI analysis

Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an OS command injection vulnerability (CWE-78) in the authenticated 'TestEmail' functionality. An attacker who is already authenticated as an administrator can submit crafted input through the TestEmail feature, causing arbitrary OS commands to be executed with root privileges on the camera. Successful exploitation yields full control of the device, which can serve as a foothold for pivoting into the surrounding network or for IoT botnet recruitment. All deployments of the listed Reolink camera models are in scope; the source data did not provide specific vulnerable firmware version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2024-12-18, confirming exploitation in the wild, and EPSS assigns a 37.5% probability of exploitation within 30 days (98th percentile); no public proof-of-concept is known and CVSS has not yet been scored.

What to do: Inventory your estate for Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W units and update them to the latest available Reolink firmware (specific fixed versions were not provided in the source data). Because these models may be end-of-life or end-of-service, discontinue use of any unit for which no current fix or mitigation is available, per CISA KEV guidance. Reduce internet exposure by avoiding direct port forwarding, placing cameras behind a VPN or firewall, and enforcing strong, unique admin credentials, since exploitation requires authenticated administrator access.

Affected
Reolink RLC-410W IP camera
Reolink C1 Pro IP camera
Reolink C2 Pro IP camera
Reolink RLC-422W IP camera
Reolink RLC-511W IP camera
Estimated exposure
mass≈1M+ cumulative devices/users across the five affected consumer models, with on the order of 100k+ Reolink cameras visible in public internet scans — Reolink is a mass-market consumer/prosumer camera brand and the five listed models were long-running sellers, while public internet-wide scans (e.g., Shodan/Censys) show on the order of 100,000+ internet-exposed Reolink devices — this is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.

CISA Known Exploited Vulnerability
Affected
Reolink Multiple IP Cameras
Required action
The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
Due date
Ransomware use
Unknown
Vendors
reolink
Products
rlc-410w firmware, c1 pro firmware, c2 pro firmware, rlc-422w firmware, rlc-511w firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.