Improper access control in RLC-410W - CVE-2021-40414
Published: January 27, 2022
RLC-410W
Reolink
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in "SetMdAlarm" in the cgiserver.cgi cgi_check_ability functionality. A remote authenticated attacker can bypass implemented security restrictions and perform a denial of service (DoS) attack.