← Back

CVE-2019-11001

nvd nist
Published: Apr 8, 2019Modified: Nov 6, 2025CISA KEV

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.

Affected (5)

5 products
Rlc 410w Firmware
C1 Pro Firmware
C2 Pro Firmware
Rlc 422w Firmware
Rlc 511w Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.227
Running on/withPlatform Versions
Reolink
Rlc 410w
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.227
Running on/withPlatform Versions
Reolink
C1 Pro
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.227
Running on/withPlatform Versions
Reolink
C2 Pro
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.227
Running on/withPlatform Versions
Reolink
Rlc 422w
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.227
Running on/withPlatform Versions
Reolink
Rlc 511w
All versions

References (5)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkExploitThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.