Products: 34
    Vulnerabilities: 115
    Known Exploited: 2
    4
    Critical Level Threats
    87
    High Level Threats
    23
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-57473

    Local Network Brute-Force Credential Compromise in Reolink Home Hub

    Last Modified: Jun 29, 2026
    Published: Jun 26, 2026

    CVE-2025-60858

    Reolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and transmits DDNS credentials in plaintext within its configuration and update scripts, allowing attackers to intercept or extract sensitive information.

    Last Modified: Apr 15, 2026
    Published: Oct 28, 2025

    CVE-2025-56800

    Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application implements lock screen password logic entirely on the client side using JavaScript within an Electron resource file. Because the password is stored and returned via a modifiable JavaScript property(a.settingsManager.lockScreenPassword), an attacker can patch the return value to bypass authentication. NOTE: this is disputed by the Supplier because the lock-screen bypass would only occur if the local user modified his own instance of the application.

    Last Modified: Nov 17, 2025
    Published: Oct 21, 2025

    CVE-2025-56799

    Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted folder name. NOTE: this is disputed by the Supplier because a crafted folder name would arise only if the local user were attacking himself.

    Last Modified: Nov 17, 2025
    Published: Oct 21, 2025

    CVE-2025-56802

    The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files allowing attackers with local access to decrypt sensitive application data stored in %APPDATA%. A different vulnerability than CVE-2025-56801. NOTE: the Supplier's position is that material is not hardcoded and is instead randomly generated on each installation of the application.

    Last Modified: Nov 17, 2025
    Published: Oct 21, 2025
    Items Per Page
    Reolink Vulnerabilities & Security CVEs | CVE-DB