#VU49880 Use of Hard-coded Cryptographic Key in P2P protocol - CVE-2020-25173
Published: January 20, 2021
P2P protocol
Reolink
Description
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to presence of a hard-coded cryptographic key. A local attacker can obtain a fixed cryptography key and compromise the Reolink P2P cameras outside of local network access.
This vulnerability affects the following Reolink devices using P2P:
- RLC-4XX series
- RLC-5XX series
- RLN-X10 series