CVE-2021-40407

7.2 HIGH CISA KEV - Actively Exploited
Published: January 28, 2022 Modified: November 03, 2025

Description

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->domain variable, that has the value of the domain parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection. An attacker can send an HTTP request to trigger this vulnerability.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1424
Source: talos-cna@cisco.com
Exploit Third Party Advisory
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1424
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40407
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

3 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.2 / 10.0
EPSS (Exploit Probability)
34.2%
97th percentile
Exploitation Status
Actively Exploited
Remediation due: 2025-01-08

Weaknesses (CWE)

Affected Vendors

reolink