HIGH · 7.2

CVE-2019-11001

On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated...

Vulnerability Description

On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.

CVSS Score

7.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ReolinkRlc-410W Firmware<= 1.0.227
ReolinkRlc-410W-
ReolinkC1 Pro Firmware<= 1.0.227
ReolinkC1 Pro-
ReolinkC2 Pro Firmware<= 1.0.227
ReolinkC2 Pro-
ReolinkRlc-422W Firmware<= 1.0.227
ReolinkRlc-422W-
ReolinkRlc-511W Firmware<= 1.0.227
ReolinkRlc-511W-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-11001?

CVE-2019-11001 is a vulnerability with a CVSS score of 7.2 (HIGH). On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated...

How severe is CVE-2019-11001?

CVE-2019-11001 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-11001?

Check the references section above for vendor advisories and patch information. Affected products include: Reolink Rlc-410W Firmware, Reolink Rlc-410W, Reolink C1 Pro Firmware, Reolink C1 Pro, Reolink C2 Pro Firmware.