← Back to browse · API

CVE-2019-11001

Severity
HIGH
CVSS
7.2
EPSS
0.37542
Risk score
66.94
CISA KEV
Yes
PoC
No
Published
2019-04-08
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2019-2715, GHSA-73C7-5G37-CMQ7
Products
Reolink:Multiple IP Cameras, n/a:n/a n/a
Sources
cisa.gov CVE-2019-11001
euvd EUVD-2019-2715

Description

On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.

References