Improper access control in RLC-410W - CVE-2021-40405
Published: January 27, 2022
RLC-410W
Reolink
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the cgiserver.cgi Upgrade API functionality. A remote authenticated attacker can bypass implemented security restrictions and perform a denial of service (DoS) attack.