← Back

CVE-2025-56800

nvd nist
Published: Oct 21, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.1
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.5 / Impact: 2.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application implements lock screen password logic entirely on the client side using JavaScript within an Electron resource file. Because the password is stored and returned via a modifiable JavaScript property(a.settingsManager.lockScreenPassword), an attacker can patch the return value to bypass authentication. NOTE: this is disputed by the Supplier because the lock-screen bypass would only occur if the local user modified his own instance of the application.

Affected (1)

Products: Reolink: Reolink
1 product
Reolink
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.18.12

References (2)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
ExploitThird Party Advisory

Timeline

No history available yet.