5.1

CVE-2025-56801

Exploit
The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data. NOTE: the Supplier's position is that material is not hardcoded and is instead randomly generated on each installation of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Reolink ≫ Reolink Version 8.18.12 SwEdition desktop
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.032
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 5.1 2.5 2.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
CWE-321 Use of Hard-coded Cryptographic Key

The product uses a hard-coded, unchangeable cryptographic key.

https://shinycolumn.notion.site/reolink-aes-iv
Third Party Advisory
Exploit
https://github.com/shinyColumn/CVE-2025-56801
Third Party Advisory
Exploit