CVE-2025-60855
Medium severity, CVSS 5.1. EPSS: 0.1% chance of exploitation in the next 30 days.
Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows attackers to load malicious firmware images, resulting in arbitrary code execution with root privileges. NOTE: this is disputed by the Supplier because the integrity of updates is instead assured via a "private encryption algorithm" and other "tamper-proof verification."
Published 2025-10-16. Last modified 2026-06-17.