CVE-2025-60856 Details
Description
Reolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attacker with physical access can connect to the exposed interface and execute arbitrary commands with root privileges. NOTE: this is disputed by the Supplier because of "certain restrictions on users privately connecting serial port cables" and because "the root user has a password and it meets the requirements of password security complexity."
A vulnerability in the Reolink Video Doorbell WiFi model DB_566128M5MP_W allows unauthorized root shell access through an exposed UART/serial console. This issue arises from improper access control, enabling attackers with physical access to the device to connect to the serial interface and execute arbitrary commands with root privileges. The vulnerability is present in the device's production firmware, where the serial console is left enabled without authentication, exposing critical system files and services.
Users are advised to prevent physical access to the devices in public or shared areas. If possible, epoxy or shield the exposed UART pads on production units. Reolink should disable the serial console in production firmware builds, implement secure boot and password-based shell protection, and restrict maintenance interfaces to authenticated engineering modes only.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 20, 2025CISA-ADP
Assessed Oct 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cybermaya.in/posts/Post-46/ | [email protected] | AdvisoryRemedyTechnical Description |
| https://reolink.com/download-center/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | CISA-ADP |
| CWE-922 | Insecure Storage of Sensitive Information | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Reolink Video Doorbell WiFi DB_566128M5MP_W | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | [email protected] |
| Oct 20, 2025 | CVE Modified | CISA-ADP |
| Oct 20, 2025 | New CVE Received | [email protected] |
Volerion