EXPOSURES › CVE-2019-11001
CVE-2019-11001
HIGH ⌖ ON CISA KEV · EXPLOITEDReolink IP cameras allow authenticated admins to execute root OS commands via the TestEmail feature, enabling full system compromise.
This authenticated command injection flaw in Reolink cameras allows attackers to run arbitrary OS commands as root, bypassing standard admin controls. For DIB organizations, this exposes IoT assets to full system compromise and violates NIST 800-171 requirements for secure system design and vulnerability management. Immediate patching and network segmentation are required to prevent lateral movement.
Shame score — A known command injection vulnerability in widely deployed IoT devices that allows root-level execution via a common admin feature.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root.