Learn about CVE-2021-44385, a high-severity vulnerability in the JSON command parser of Reolink RLC-410W v3.0.0.136_20121102 that allows for denial of service by triggering system reboots.
A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102, leading to a reboot when receiving a specially-crafted HTTP request. This CVE has a CVSS base score of 8.6.
Understanding CVE-2021-44385
What is CVE-2021-44385?
The vulnerability in the JSON command parser of Reolink RLC-410W v3.0.0.136_20121102 allows for a denial of service via a malicious HTTP request.
The Impact of CVE-2021-44385
The vulnerability has a high severity level with CVSS base score 8.6, resulting in a denial of service by triggering a system reboot through crafted HTTP requests.
Technical Details of CVE-2021-44385
Vulnerability Description
The issue resides in the cgiserver.cgi JSON command parser of Reolink RLC-410W v3.0.0.136_20121102, where improper handling of HTTP requests can cause the device to reboot.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability can be exploited by sending a specially-crafted HTTP request to the affected device, triggering an unexpected reboot.
Mitigation and Prevention
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates
Ensure timely installation of security patches and firmware updates provided by Reolink to mitigate the vulnerability.