5.1

CVE-2025-56801

Exploit
The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data. NOTE: the Supplier's position is that material is not hardcoded and is instead randomly generated on each installation of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ReolinkReolink Version8.18.12 SwEditiondesktop
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.032
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 5.1 2.5 2.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
CWE-321 Use of Hard-coded Cryptographic Key

The product uses a hard-coded, unchangeable cryptographic key.

https://shinycolumn.notion.site/reolink-aes-iv
Third Party Advisory
Exploit
https://github.com/shinyColumn/CVE-2025-56801
Third Party Advisory
Exploit