CVE-2021-40407
KEV PoC largeAuthenticated OS Command Injection in Reolink RLC-410W IP Camera
CISA: Reolink RLC-410W IP Camera OS Command Injection Vulnerability
CVE-2021-40407 is an authenticated OS command injection flaw (CWE-78) in the network settings functionality of Reolink RLC-410W IP cameras. An attacker with valid credentials can submit crafted input through the network settings interface, causing injected operating-system commands to execute on the camera's firmware. Successful exploitation yields arbitrary command execution on the device, allowing the attacker to control the camera, alter configuration or video streams, and potentially pivot into the network the camera sits on. Only the Reolink RLC-410W is named as affected, and CISA warns the product may be end-of-life or end-of-service, so a current mitigation or fix may not be available for all deployments. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-12-18, confirming exploitation in the wild; it sits in the 99th EPSS percentile with a 47.6% probability of exploitation within 30 days, though ransomware use is unconfirmed and no public proof-of-concept is known.
What to do: Check whether your RLC-410W is still supported and, if so, update to the latest Reolink firmware; CISA cautions the model may be end-of-life/end-of-service, in which case no fix may be available. Because exploitation requires valid credentials but is confirmed in the wild, restrict administrative access, disable WAN exposure such as port forwarding and UPnP, and place cameras on an isolated network segment. If no current mitigation or firmware is available, replace or discontinue the device.
| Reolink RLC-410W IP Camera | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->domain variable, that has the value of the domain parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection. An attacker can send an HTTP request to trigger this vulnerability.
- Affected
- Reolink RLC-410W IP Camera
- Required action
- The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- reolink
- Products
- rlc-410w firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H