← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-40419

A firmware update vulnerability exists in the 'factory' binary of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted series of network requests can lead to arbitrary firmware update. An attacker can send a sequence of requests to trigger this vulnerability.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:1.23%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-489 ↗CWE-489: Leftover Debug Code

Affected Products & Versions

Vendor Product Affected Versions
reolink rlc-410w_firmware 3.0.0.136_20121102
reolink rlc-410w all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.232%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityTalos · Researcher · USA
Reserved2021-09-01T00:00:00
Published2022-01-28T19:10:07
Last Updated2025-04-15T19:21:23

LINK COPIED TO CLIPBOARD