CVE-2019-11001 is an OS command injection vulnerability affecting several Reolink IP camera models (RLC-410W, C1 Pro, C2 Pro, RLC-422W, RLC-511W) through firmware version 1.0.227. An authenticated administrator can exploit this by injecting shell metacharacters into the "TestEmail" functionality's addr1 field, allowing arbitrary OS command execution as root. This vulnerability carries a high CVSS score of 7.2, indicating a network-based attack with high impact on confidentiality, integrity, and availability, requiring high privileges but low attack complexity. Notably, this CVE is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, despite a lack of public exploit code or significant media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.227CPE matchmatch criteria | cpe:2.3:o:reolink:rlc-410w_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.227CPE matchmatch criteria | cpe:2.3:o:reolink:c1_pro_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.227CPE matchmatch criteria | cpe:2.3:o:reolink:c2_pro_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.227CPE matchmatch criteria | cpe:2.3:o:reolink:rlc-422w_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.227CPE matchmatch criteria | cpe:2.3:o:reolink:rlc-511w_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.