Reolink develops a focused line of networked surveillance cameras and recording devices, with vulnerability exposure concentrated in products such as the RLC-410W and related firmware. The vendor's disclosures center on input-validation, access-control, and command-injection weaknesses alongside hard-coded cryptographic material and incorrect default permissions, a pattern characteristic of embedded network devices where firmware update cycles and deployment longevity create sustained risk. The moderate volume of disclosures and top-percentile prominence reflect the broad deployment of these devices across small-business and consumer surveillance installations, where network-facing management interfaces and long product lifecycles amplify the impact of authentication and input-handling flaws. Defenders should inventory Reolink devices, prioritize firmware updates, and restrict management access; live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Reolink over time
Signals from CVEs in this vendor scope (106 CVEs).
106 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40407HIGH An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->doma | Jan 28, 2022 | 7.2 | 82 | YES | NO |
CVE-2019-11001HIGH On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as r | Apr 8, 2019 | 7.2 | 80 | YES | NO |
CVE-2021-40150HIGH The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker ca | Jul 17, 2022 | 7.5 | 36 | NO | YES |
CVE-2021-40412HIGH An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [8] the devname variable, that has the value of | Jan 28, 2022 | 7.2 | 36 | NO | NO |
CVE-2021-40410HIGH An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [4] the dns_data->dns1 variable, that has the | Jan 28, 2022 | 7.2 | 36 | NO | NO |
CVE-2025-55619CRITICAL Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker can leverage this vulnerability to decrypt access tokens and | Aug 22, 2025 | 9.8 | 34 | NO | NO |
CVE-2021-40149MEDIUM The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the | Jul 17, 2022 | 5.9 | 33 | NO | YES |
CVE-2025-55637CRITICAL Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to contain a command injection vulnerability via the setddns_pip_system() | Aug 22, 2025 | 9.8 | 31 | NO | NO |
CVE-2021-40409CRITICAL An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->pass | Jan 28, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-40408CRITICAL An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->user | Jan 28, 2022 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (106 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Reolink.
Media articles that mention a CVE ID that affects a product developed by Reolink — matched by CVE ID, not by vendor name.