Skip to content
COOEY

FAIL › dossier

Reolink

VENDOR

· dossier confidence 20%

Reolink, a Chinese-based security solutions provider, has experienced significant security lapses, highlighted by high-severity remote code execution vulnerabilities in their IP cameras. These incidents suggest a need for closer scrutiny of their cybersecurity posture and practices.

PROFILE
CategorysecurityWhat they doReolink is a provider of video surveillance solutions, including IP cameras and security systems. Websitehttps://www.reolink.com ↗
SECURITY POSTURE

Reolink has faced multiple security vulnerabilities, indicating a potential lack of robust security practices.

Notable failures
  • CVE-2021-40407: High [RCE] - Authenticated attackers could execute arbitrary OS commands via network settings.
  • CVE-2019-11001: High [RCE] - Authenticated admins could execute root OS commands via the TestEmail feature.
Patterns: Repeated unpatched edge-device RCEs
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2024-12-18 CVE-2021-40407 high Reolink RLC-410W IP cameras allow authenticated attackers to execute arbitrary OS commands via network settings, enabling remote compromise of connected devices.
2024-12-18 CVE-2019-11001 high Reolink IP cameras allow authenticated admins to execute root OS commands via the TestEmail feature, enabling full system compromise.
Open questions: How has Reolink addressed these vulnerabilities? · What is the current state of Reolink's security practices?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-06 03:44:55.291642+00:00