5.1

CVE-2025-56802

Exploit
The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files allowing attackers with local access to decrypt sensitive application data stored in %APPDATA%. A different vulnerability than CVE-2025-56801. NOTE: the Supplier's position is that material is not hardcoded and is instead randomly generated on each installation of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Reolink ≫ Reolink Version 8.18.12 SwEdition desktop
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.026
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 5.1 2.5 2.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
CWE-321 Use of Hard-coded Cryptographic Key

The product uses a hard-coded, unchangeable cryptographic key.

https://shinycolumn.notion.site/reolink-aes-key
Third Party Advisory
Exploit
https://github.com/shinyColumn/CVE-2025-56802
Third Party Advisory
Exploit