#VU60065 Improper access control in RLC-410W - CVE-2021-40416
Published: January 27, 2022
RLC-410W
Reolink
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in "Get APIs" in the cgiserver.cgi cgi_check_ability functionality. A remote authenticated attacker can bypass implemented security restrictions and perform a denial of service (DoS) attack.