ZeroHour

CVE-2021-40412

PoC
CVSS 3.1
7.2 high
EPSS
27%p98
Published
()
Modified
Description

An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [8] the devname variable, that has the value of the name parameter provided through the SetDevName API, is not validated properly. This would lead to an OS command injection.

Vendors
reolink
Products
rlc-410w firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news