← Back to CVE List
Vulnerability Intelligence Report
Reolink Multiple IP Cameras OS Command Injection Vulnerability

CVE-2019-11001

On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.2
HIGH
Exploitability:1.3
Impact Score:5.9
EPSS Probability:38.37%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-78 ↗CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Affected Products & Versions

Vendor Product Affected Versions
reolink rlc-410w_firmware all
reolink rlc-410w all
reolink c1_pro_firmware all
reolink c1_pro all
reolink c2_pro_firmware all
reolink c2_pro all
reolink rlc-422w_firmware all
reolink rlc-422w all
reolink rlc-511w_firmware all
reolink rlc-511w all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
38.369%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2019-04-08T00:00:00
Published2019-04-08T17:00:21
Last Updated2025-10-21T23:45:40

LINK COPIED TO CLIPBOARD