Threat intelligence report · CISA KEV

CVE-2019-11001: Reolink Multiple IP Cameras OS Command Injection Vulnerability

Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root. Required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

· high severity · unattributed attribution

Evidence and provenance

Original source
CISA KEV report ↗
Published
2024-12-18T00:00:00Z
Confidence basis
No actor match
Record ID
78616b92f37071723586

Vulnerabilities

CVE-2019-11001

Use and citation

Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.