Skip to main content

Vendor archive

reolink CVEs

Beta · best-effort

106 CVEs tagged to vendor reolink5 Critical, 86 High, 15 Medium, 0 Low, 0 Unrated.

CVE-2025-56802

Published Oct 21, 2025

The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files allowing attackers with local access to decrypt sensitive…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-56801

Published Oct 21, 2025

The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-56800

Published Oct 21, 2025

Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application implements lock screen password logic entirely on the client si…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-56799

Published Oct 21, 2025

Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted folder name. NOTE: this is disputed by the S…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55625

Published Aug 22, 2025

An open redirect vulnerability in Reolink v4.54.0.4.20250526 allows attackers to redirect users to a malicious site via a crafted URL. NOTE: this is disputed by the Supplier becau…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55624

Published Aug 22, 2025

An intent redirection vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access internal functions or access non-public components.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55623

Published Aug 22, 2025

An issue in the lock screen component of Reolink v4.54.0.4.20250526 allows attackers to bypass authentication via using an ADB (Android Debug Bridge).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55622

Published Aug 22, 2025

Reolink v4.54.0.4.20250526 was discovered to contain a task hijacking vulnerability due to inappropriate taskAffinity settings. NOTE: this is disputed by the Supplier because it i…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55621

Published Aug 22, 2025

An Insecure Direct Object Reference (IDOR) vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access and download other users' profile photos via a craft…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55620

Published Aug 22, 2025

A cross-site scripting (XSS) vulnerability in the valuateJavascript() function of Reolink v4.54.0.4.20250526 allows attackers to execute arbitrary web scripts or HTML via a crafte…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55619

Published Aug 22, 2025

Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker can leverage this vulnerability to decrypt access tokens and…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-40150

Published Jul 17, 2022

The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-40149

Published Jul 17, 2022

The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 106 CVEsPage 1 of 5