CVE-2021-40407 Details
Description
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->domain variable, that has the value of the domain parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection. An attacker can send an HTTP request to trigger this vulnerability.
A command injection vulnerability has been identified in the Reolink RLC-410W IP camera, specifically in the device's network settings feature. This vulnerability, present in version 3.0.0.136_20121102, allows authenticated users to execute arbitrary operating system commands by sending specially crafted HTTP requests. The issue arises because the camera's application programming interfaces (APIs) for managing Dynamic Domain Name System (DDNS) and Domain Name System (DNS) settings do not properly validate user input before it is processed, leading to potential exploitation.
Users are advised to discontinue use of the Reolink RLC-410W IP camera if no current mitigation is available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 21, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40407 | CISA-ADP | US Government Resource |
| https://talosintelligence.com/vulnerability_reports/TALOS-2021-1424 | CVE | ExploitThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2021-1424 | [email protected] | ExploitThird Party Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Reolink RLC-410W IP Camera OS Command Injection Vulnerability | Dec 18, 2024 | Jan 8, 2025 | The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| reolink rlc-410w firmware | 3.0.0.136_20121102 |
CPE
Remediation
| |
| reolink rlc-410w | All versions |
CPE
Remediation
| |
Change History
14 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Apr 2, 2025 | Modified Analysis | [email protected] |
| Dec 19, 2024 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jul 29, 2022 | Modified Analysis | [email protected] |
| Apr 28, 2022 | CVE Modified | [email protected] |
| Apr 19, 2022 | CVE Modified | [email protected] |
| Feb 3, 2022 | Initial Analysis | [email protected] |