← Back to CVE List
Vulnerability Intelligence Report

CVE-2025-55621

disputed

An Insecure Direct Object Reference (IDOR) vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access and download other users' profile photos via a crafted URL. NOTE: this is disputed by the Supplier because it is intentional behavior; the photos are part of a social platform on which users expect to find one another.

No Active Exploit Signals
CVSS Base Score
6.5
MEDIUM
Exploitability:3.9
Impact Score:2.6
EPSS Probability:0.22%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-639 ↗CWE-639 Authorization Bypass Through User-Controlled Key

Affected Products & Versions

Vendor Product Affected Versions
reolink reolink 4.54.0.4.20250526

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.222%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2025-08-13T00:00:00
Published2025-08-22T00:00:00
Last Updated2025-09-04T14:37:30

LINK COPIED TO CLIPBOARD