FAIL › dossier
Reolink
VENDOR· dossier confidence 20%
Reolink, a Chinese-based security solutions provider, has experienced significant security lapses, highlighted by high-severity remote code execution vulnerabilities in their IP cameras. These incidents suggest a need for closer scrutiny of their cybersecurity posture and practices.
PROFILE
CategorysecurityWhat they doReolink is a provider of video surveillance solutions, including IP cameras and security systems.
Websitehttps://www.reolink.com ↗
SECURITY POSTURE
Reolink has faced multiple security vulnerabilities, indicating a potential lack of robust security practices.
Notable failures
- CVE-2021-40407: High [RCE] - Authenticated attackers could execute arbitrary OS commands via network settings.
- CVE-2019-11001: High [RCE] - Authenticated admins could execute root OS commands via the TestEmail feature.
Patterns: Repeated unpatched edge-device RCEs
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-12-18 | CVE-2021-40407 | high | Reolink RLC-410W IP cameras allow authenticated attackers to execute arbitrary OS commands via network settings, enabling remote compromise of connected devices. |
| 2024-12-18 | CVE-2019-11001 | high | Reolink IP cameras allow authenticated admins to execute root OS commands via the TestEmail feature, enabling full system compromise. |
DOSSIER SOURCES
- July 2026 Highlights - Reolink Camera Community · community.reolink.com
- CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- How Do I Update My Ip Camera Firmware - surveillanceguides.com · surveillanceguides.com
Open questions: How has Reolink addressed these vulnerabilities? · What is the current state of Reolink's security practices?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-06 03:44:55.291642+00:00