CVE-2019-11001
Reolink Multiple IP Cameras OS Command Injection Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 7.2
- EPSS
- 38.4% 백분위 98.4% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2025.01.08
- 공개일
- 2019.04.09
CISA KEV에 등록된 실제 악용 확인 취약점
On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.
공급사 Reolink
제품 Multiple IP Cameras
영향 버전 n/a, <= 1.0.227
수정 버전 공식 출처에서 확인 필요
The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
조치 기한: 2025.01.08CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE CWE-78
KEV 등록일 2024.12.18
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://reolink.com/product-eol/ ; https://reolink.com/download-center/ ; https://nvd.nist.gov/vuln/detail/CVE-2019-11001
EPSS 데이터 기준일 2026.06.27