Vulnerability record · CVE-2019-11001 · published 8 April 2019
CVE-2019-11001: Reolink IP cameras OS command injection via TestEmail
Reolink · Rlc 410w Firmware
Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W and RLC-511W devices through firmware 1.0.227 allow an authenticated admin to inject OS commands through the TestEmail functionality. Shell metacharacters placed in the addr1 field are executed as root, giving full control of the camera. The flaw is a classic OS command injection (CWE-78) and is listed in CISA KEV, so it is being exploited in the wild.
Description
On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw gives root command execution, has public exploit code, and is in CISA KEV with a high EPSS score, though it requires authenticated admin access.
What it is
Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W and RLC-511W devices through firmware 1.0.227 allow an authenticated admin to inject OS commands through the TestEmail functionality. Shell metacharacters placed in the addr1 field are executed as root, giving full control of the camera. The flaw is a classic OS command injection (CWE-78) and is listed in CISA KEV, so it is being exploited in the wild.
Impact
An attacker with admin credentials gains root-level command execution on the device, allowing arbitrary code, persistence, and use of the camera as a foothold into the network. Because the commands run as root, the attacker can read or alter camera data and pivot to other hosts.
Attack surface
The vulnerability is reachable over the network through the device's web/management interface, specifically the TestEmail feature. It requires authenticated admin access; no user interaction beyond that is needed, per the CVSS vector AV:N/AC:L/PR:H/UI:N.
Exploitation
CVE-2019-11001 is in CISA KEV (added 2024-12-18) and public exploit code is referenced, so exploitation is confirmed and active. EPSS gives a 30-day probability of 0.375 (98th percentile), indicating high likelihood of attempted exploitation.
What to do
- Apply the latest Reolink firmware for the affected models; if no fixed firmware exists, discontinue use of the device as CISA advises.
- Restrict management interface access to a trusted network or VPN and never expose the camera web UI to the internet.
- Change default admin credentials and enforce strong unique passwords; limit admin accounts to those who truly need them.
- Monitor for and block shell metacharacters in the TestEmail addr1 field at any reverse proxy or WAF in front of the device.
- Segment cameras on an isolated VLAN with no outbound access to internal management networks.
Detection
- Search device or web logs for TestEmail requests containing shell metacharacters (;, |, &, $(), backticks) in the addr1 parameter.
- Monitor camera processes and outbound connections for unexpected child processes or connections to unknown hosts.
- Alert on admin logins to camera management interfaces from unusual source IPs or outside normal hours.
- Use network monitoring to detect command-and-control or scanning traffic originating from camera VLANs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-11001 to the Known Exploited Vulnerabilities catalog on 18 December 2024 as "Reolink Multiple IP Cameras OS Command Injection Vulnerability". Required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable. Federal deadline 8 January 2025.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/mcw0/PoC/blob/master/Reolink-IPC-RCE.py | ExploitThird Party Advisory |
| https://www.vdoo.com/blog/working-with-the-community-%E2%80%93-significant-vulnerabilities-in-reolink-cameras/ | Broken LinkExploitThird Party Advisory |
| https://github.com/mcw0/PoC/blob/master/Reolink-IPC-RCE.py | ExploitThird Party Advisory |
| https://www.vdoo.com/blog/working-with-the-community-%E2%80%93-significant-vulnerabilities-in-reolink-cameras/ | Broken LinkExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11001 | US Government Resource |
Track CVE-2019-11001 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-11001), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.