Vulnerability Description
Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker can leverage this vulnerability to decrypt access tokens and web session tokens stored inside the app via reverse engineering.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Reolink | Reolink | 4.54.0.4.20250526 |
Related Weaknesses (CWE)
References
- https://cwe.mitre.org/data/definitions/321.htmlProduct
- https://cwe.mitre.org/data/definitions/329.htmlProduct
- https://developer.android.com/reference/kotlin/androidx/security/crypto/EncrypteThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-25173Not Applicable
- https://www.notion.so/Reolink-Android-App-Uses-Hardcoded-AES-Key-and-IV-for-SensExploitThird Party Advisory
- https://relieved-knuckle-264.notion.site/Reolink-Android-App-Uses-Hardcoded-AES-ExploitThird Party Advisory
FAQ
What is CVE-2025-55619?
CVE-2025-55619 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker can leverage this vulnerability to decrypt access tokens and web session tokens s...
How severe is CVE-2025-55619?
CVE-2025-55619 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-55619?
Check the references section above for vendor advisories and patch information. Affected products include: Reolink Reolink.