ZeroHour

CVE-2021-40407

KEV PoC large

Authenticated OS Command Injection in Reolink RLC-410W IP Camera

CISA: Reolink RLC-410W IP Camera OS Command Injection Vulnerability

CVSS 3.1
7.2 high
EPSS
48%p99
Published
()
KEV added
AI analysis

CVE-2021-40407 is an authenticated OS command injection flaw (CWE-78) in the network settings functionality of Reolink RLC-410W IP cameras. An attacker with valid credentials can submit crafted input through the network settings interface, causing injected operating-system commands to execute on the camera's firmware. Successful exploitation yields arbitrary command execution on the device, allowing the attacker to control the camera, alter configuration or video streams, and potentially pivot into the network the camera sits on. Only the Reolink RLC-410W is named as affected, and CISA warns the product may be end-of-life or end-of-service, so a current mitigation or fix may not be available for all deployments. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-12-18, confirming exploitation in the wild; it sits in the 99th EPSS percentile with a 47.6% probability of exploitation within 30 days, though ransomware use is unconfirmed and no public proof-of-concept is known.

What to do: Check whether your RLC-410W is still supported and, if so, update to the latest Reolink firmware; CISA cautions the model may be end-of-life/end-of-service, in which case no fix may be available. Because exploitation requires valid credentials but is confirmed in the wild, restrict administrative access, disable WAN exposure such as port forwarding and UPnP, and place cameras on an isolated network segment. If no current mitigation or firmware is available, replace or discontinue the device.

Affected
Reolink RLC-410W IP Camera
Estimated exposure
largeon the order of hundreds of thousands of deployed RLC-410W cameras (exact install counts unpublished) — The RLC-410 line is Reolink's best-selling camera family and Reolink devices appear broadly in public internet-exposure scans, but no per-model install figures are published, so this is a six-figure order-of-magnitude estimate for the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->domain variable, that has the value of the domain parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection. An attacker can send an HTTP request to trigger this vulnerability.

CISA Known Exploited Vulnerability
Affected
Reolink RLC-410W IP Camera
Required action
The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
Due date
Ransomware use
Unknown
Vendors
reolink
Products
rlc-410w firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news