CVE-2019-11001
On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.
Published:Apr 8, 2019
Last Modified:Nov 6, 2025
EPS:Apr 8, 2019
EPSS Score:0.54887
CVSS Score:7.2
CISA Notification
Description
On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.
Required Action:
The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
Notes:
No extra notes provided.
Due Date
Jan 8, 2025
611 days ago
Alert Date
Dec 18, 2024
632 days ago
Affected Products
Vendor
Product
Action
Vendor
Reolink
Product
C1 Pro
Reolink
C1 Pro
Vendor
Reolink
Product
C1 Pro Firmware
Reolink
C1 Pro Firmware
Vendor
Reolink
Product
C2 Pro
Reolink
C2 Pro
Vendor
Reolink
Product
C2 Pro Firmware
Reolink
C2 Pro Firmware
Vendor
Reolink
Product
Rlc-410w
Reolink
Rlc-410w
Vendor
Reolink
Product
Rlc-410w Firmware
Reolink
Rlc-410w Firmware
Vendor
Reolink
Product
Rlc-422w
Reolink
Rlc-422w
Vendor
Reolink
Product
Rlc-422w Firmware
Reolink
Rlc-422w Firmware
Vendor
Reolink
Product
Rlc-511w
Reolink
Rlc-511w
Vendor
Reolink
Product
Rlc-511w Firmware
Reolink
Rlc-511w Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
