← Back to browse · API

CVE-2021-40412

Severity
CRITICAL
CVSS
9.1
EPSS
0.27477
Risk score
46.02
CISA KEV
No
PoC
No
Published
2022-01-28
Modified
2025-04-15
First seen
2026-08-07
Aliases
EUVD-2021-27589, GHSA-8HCX-PW9G-W24X
Products
n/a:n/a n/a
Sources
euvd EUVD-2021-27589

Description

An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [8] the devname variable, that has the value of the name parameter provided through the SetDevName API, is not validated properly. This would lead to an OS command injection.

References