CVE-2021-44404: Reolink RLC-410W Firmware

High severity, CVSS 7.7. EPSS: 1.2% chance of exploitation in the next 30 days.

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetZoomFocus param is not object. An attacker can send an HTTP request to trigger this vulnerability.

Affected products

  • Reolink RLC-410W Firmware: version 3.0.0.136_20121102 only

Published 2022-01-28. Last modified 2026-06-17.