CVE-2019-11001
KEV PoC ×2massAuthenticated OS Command Injection in Reolink IP Cameras (CVE-2019-11001)
CISA: Reolink Multiple IP Cameras OS Command Injection Vulnerability
Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an OS command injection vulnerability (CWE-78) in the authenticated 'TestEmail' functionality. An attacker who is already authenticated as an administrator can submit crafted input through the TestEmail feature, causing arbitrary OS commands to be executed with root privileges on the camera. Successful exploitation yields full control of the device, which can serve as a foothold for pivoting into the surrounding network or for IoT botnet recruitment. All deployments of the listed Reolink camera models are in scope; the source data did not provide specific vulnerable firmware version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2024-12-18, confirming exploitation in the wild, and EPSS assigns a 37.5% probability of exploitation within 30 days (98th percentile); no public proof-of-concept is known and CVSS has not yet been scored.
What to do: Inventory your estate for Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W units and update them to the latest available Reolink firmware (specific fixed versions were not provided in the source data). Because these models may be end-of-life or end-of-service, discontinue use of any unit for which no current fix or mitigation is available, per CISA KEV guidance. Reduce internet exposure by avoiding direct port forwarding, placing cameras behind a VPN or firewall, and enforcing strong, unique admin credentials, since exploitation requires authenticated administrator access.
| Reolink RLC-410W IP camera | — |
| Reolink C1 Pro IP camera | — |
| Reolink C2 Pro IP camera | — |
| Reolink RLC-422W IP camera | — |
| Reolink RLC-511W IP camera | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.
- Affected
- Reolink Multiple IP Cameras
- Required action
- The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- reolink
- Products
- rlc-410w firmware, c1 pro firmware, c2 pro firmware, rlc-422w firmware, rlc-511w firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.