Security Advisory

CVE-2019-11001

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-04-08 17:00:21
Last updated 2025-10-21 23:45:40
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.