ZeroHour
Cisco Talospublished ()ingested

Vulnerability Spotlight: WiFi-connected security camera could be manipulated to spy on communications, among other malicious actions

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-21217
An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_20121102.

An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted network request can lead to an out-of-bounds write. An attacker can send an HTTP request to trigger this vulnerability.

NVD description · AI analysis pending
9.8
group max
1%
  • reolink rlc-410w firmware
CVE-2021-44354
+1 in the same advisory: …40405
Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102.

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

NVD description · AI analysis pending
7.5
group max
2% PoC
  • reolink rlc-410w firmware
CVE-2021-40407
Authenticated OS Command Injection in Reolink RLC-410W IP Camera

CVE-2021-40407 is an authenticated OS command injection flaw (CWE-78) in the network settings functionality of Reolink RLC-410W IP cameras. An attacker with valid credentials can submit crafted input through the network settings interface, causing injected operating-system commands to execute on the camera's firmware. Successful exploitation yields arbitrary command execution on the device, allowing the attacker to control the camera, alter configuration or video streams, and potentially pivot into the network the camera sits on. Only the Reolink RLC-410W is named as affected, and CISA warns the product may be end-of-life or end-of-service, so a current mitigation or fix may not be available for all deployments. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-12-18, confirming exploitation in the wild; it sits in the 99th EPSS percentile with a 47.6% probability of exploitation within 30 days, though ransomware use is unconfirmed and no public proof-of-concept is known.

Do: Check whether your RLC-410W is still supported and, if so, update to the latest Reolink firmware; CISA cautions the model may be end-of-life/end-of-service, in which case no fix may be available. Because exploitation requires valid credentials but is confirmed in the wild, restrict administrative access, disable WAN exposure such as port forwarding and UPnP, and place cameras on an isolated network segment. If no current mitigation or firmware is available, replace or discontinue the device.

7.248% KEV PoC
  • Reolink RLC-410W IP Camera
largeon the order of hundreds of thousands of deployed RLC-410W cameras (exact install counts unpublished)
Full article492 words · extracted from blog.talosintelligence.com · click to collapse

Wednesday, January 26, 2022 16:09

Francesco Benvenuto of Cisco Talos discovered these vulnerabilities.

Cisco Talos recently discovered several vulnerabilities in the Reolink RLC-410W security camera that could allow an attacker to perform several malicious actions, including performing man-in-the-middle attacks, stealing user login credentials and more.

The Reolink RLC-410W is a WiFi-connected security camera. The camera includes motion detection functionalities and multiple ways to save and view the recordings. The vulnerabilities Talos discovered exist in various functions and features of the camera. Some of these exploits could be combined, as well, to reboot the camera without authentication or run certain APIs.

There are five denial-of-service vulnerabilities that could allow an adversary to make the web service unresponsive and restart the device if they send specific network requests to the target:

TALOS-2022-1450 (CVE-2022-21801) is also a denial-of-service vulnerability, but rather than dealing with the web service, it affects a binary called “netserver.”

TALOS-2021-1420 (CVE-2021-40404) is an authentication bypass vulnerability that could allow, in combination with other vulnerabilities, to execute privileged action without authentication. If combined with TALOS-2021-1421, 1422 or 1425, the attacker could cause a denial-of-service without authentication.

TALOS-2021-1425 is also unique because a low-privileged user could reformat the SD card in the camera. This API allows only admin accounts to execute it. But if this vulnerability is combined with 1420, no authentication is required to delete recordings on the camera.

Two other vulnerabilities, TALOS-2022-1447 (CVE-2022-21134) and TALOS-2021-1428 (CVE-2021-40419) can also be triggered with malicious network requests. However, in those cases, it only causes the camera to update to the latest firmware without the user’s knowledge. If the attacker exploits TALOS-2021-1428, they could even force the upgrade without any MITM involved.

TALOS-2022-1445 (CVE-2022-21217) and TALOS-2022-1451 (CVE-2022-21796) are issues in two different functionalities of the camera’s firmware. An attacker could exploit these vulnerabilities to cause out-of-bounds write conditions.

TALOS-2021-1424 (CVE-2021-40407 - CVE-2021-40412), which has a severity score of 9.1 out of a possible 10, could also be exploited to execute arbitrary code on the targeted device.

Lastly, there are two information disclosure vulnerabilities in the camera: TALOS-2022-1446 (CVE-2022-21236) and TALOS-2022-1448 (CVE-2022-21199). An attacker could exploit either of these to view sensitive information that could be used in man-in-the-middle attacks against the device.

Cisco Talos worked with Reolink to ensure that this issue is resolved and an update is available for affected customers, all in adherence to Cisco’s vulnerability disclosure policy.

Users are advised to update the Reolink RLC-410W v3.0.0.136_20121102, which is tested and confirmed to be affected by these vulnerabilities.

The following SNORTⓇ rules will detect exploitation attempts against these vulnerabilities: 58691 - 58693, 58698, 58699, 58718, 58817 – 58720 and 58926 – 58928. Additional rules may be released in the future and current rules are subject to change, pending additional vulnerability information. For the most current rule information, please refer to your Cisco Secure Firewall management center or Snort.org.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/vuln-spotlight-reolink-cameras/