An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability...
Vulnerability Description
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. All the Get APIs that are not included in cgi_check_ability are already executable by any logged-in users. An attacker can send an HTTP request to trigger this vulnerability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-40416
Credits & Attribution
No credits recorded in the NVD database.
More from reolink
View All →Affected Vendor
reolink
View all reports →