Skip to content
COOEY

EXPOSURES › CVE-2019-11001

CVE-2019-11001

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-12-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-11001 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildunpatchedransomware

Reolink IP cameras allow authenticated admins to execute root OS commands via the TestEmail feature, enabling full system compromise.

This authenticated command injection flaw in Reolink cameras allows attackers to run arbitrary OS commands as root, bypassing standard admin controls. For DIB organizations, this exposes IoT assets to full system compromise and violates NIST 800-171 requirements for secure system design and vulnerability management. Immediate patching and network segmentation are required to prevent lateral movement.

Shame score — A known command injection vulnerability in widely deployed IoT devices that allows root-level execution via a common admin feature.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.