EXPOSURES › CVE-2021-40407
CVE-2021-40407
HIGH ⌖ ON CISA KEV · EXPLOITEDReolink RLC-410W IP cameras allow authenticated attackers to execute arbitrary OS commands via network settings, enabling remote compromise of connected devices.
This authenticated command injection flaw in the RLC-410W allows attackers to execute arbitrary OS commands through network settings, posing a severe risk to DIB organizations relying on compromised IoT devices for surveillance or access control. Because the vulnerability is actively exploited and linked to ransomware campaigns, vendors must prioritize patching and DIB orgs should audit all Reolink-connected endpoints for unpatched firmware.
Shame score — An authenticated command injection flaw actively exploited in the wild that enables remote OS command execution on a widely deployed consumer security device.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.