← Vulnerability feed

Vulnerability record · CVE-2019-11001 · published 8 April 2019

CVE-2019-11001: Reolink IP cameras OS command injection via TestEmail

Reolink · Rlc 410w Firmware

Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W and RLC-511W devices through firmware 1.0.227 allow an authenticated admin to inject OS commands through the TestEmail functionality. Shell metacharacters placed in the addr1 field are executed as root, giving full control of the camera. The flaw is a classic OS command injection (CWE-78) and is listed in CISA KEV, so it is being exploited in the wild.

7.2 CVSS 3.1 High CISA KEV since 18 Dec 2024 EPSS 38% · top 1.5% CWE-78 · OS command injection
7.2CVSS 3.1 base score, v2 9.0
38%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
5Affected product versions listed by NVD
5References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw gives root command execution, has public exploit code, and is in CISA KEV with a high EPSS score, though it requires authenticated admin access.

What it is

Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W and RLC-511W devices through firmware 1.0.227 allow an authenticated admin to inject OS commands through the TestEmail functionality. Shell metacharacters placed in the addr1 field are executed as root, giving full control of the camera. The flaw is a classic OS command injection (CWE-78) and is listed in CISA KEV, so it is being exploited in the wild.

Impact

An attacker with admin credentials gains root-level command execution on the device, allowing arbitrary code, persistence, and use of the camera as a foothold into the network. Because the commands run as root, the attacker can read or alter camera data and pivot to other hosts.

Attack surface

The vulnerability is reachable over the network through the device's web/management interface, specifically the TestEmail feature. It requires authenticated admin access; no user interaction beyond that is needed, per the CVSS vector AV:N/AC:L/PR:H/UI:N.

Exploitation

CVE-2019-11001 is in CISA KEV (added 2024-12-18) and public exploit code is referenced, so exploitation is confirmed and active. EPSS gives a 30-day probability of 0.375 (98th percentile), indicating high likelihood of attempted exploitation.

What to do

  • Apply the latest Reolink firmware for the affected models; if no fixed firmware exists, discontinue use of the device as CISA advises.
  • Restrict management interface access to a trusted network or VPN and never expose the camera web UI to the internet.
  • Change default admin credentials and enforce strong unique passwords; limit admin accounts to those who truly need them.
  • Monitor for and block shell metacharacters in the TestEmail addr1 field at any reverse proxy or WAF in front of the device.
  • Segment cameras on an isolated VLAN with no outbound access to internal management networks.

Detection

  • Search device or web logs for TestEmail requests containing shell metacharacters (;, |, &, $(), backticks) in the addr1 parameter.
  • Monitor camera processes and outbound connections for unexpected child processes or connections to unknown hosts.
  • Alert on admin logins to camera management interfaces from unusual source IPs or outside normal hours.
  • Use network monitoring to detect command-and-control or scanning traffic originating from camera VLANs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-11001 to the Known Exploited Vulnerabilities catalog on 18 December 2024 as "Reolink Multiple IP Cameras OS Command Injection Vulnerability". Required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable. Federal deadline 8 January 2025.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-11001 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2021-40407Reolink RLC-410W camera DDNS domain OS command injectionThe Reolink RLC-410W firmware v3.0.0.136_20121102 fails to validate the ddns->domain value supplied through the SetDdns API, allowing OS command inje…KEVEPSS 48%analysed9.8CVE-2022-21217Reolink rlc-410w firmware out-of-bounds write vulnerabilityAn out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted networ…EPSS 1.2%9.8CVE-2021-40408Reolink rlc-410w firmware os command injection vulnerabilityAn OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], bas…EPSS 3.7%9.8CVE-2021-40409Reolink rlc-410w firmware os command injection vulnerabilityAn OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], bas…EPSS 3.7%8.8CVE-2021-40416Reolink rlc-410w firmware improper access control vulnerabilityAn incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. Al…EPSS 0.87%8.2CVE-2022-21796Reolink rlc-410w firmware improper input validation vulnerabilityA memory corruption vulnerability exists in the netserver parse_command_list functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-craft…EPSS 1.1%7.7CVE-2021-44413Reolink rlc-410w firmware improper input validation vulnerabilityA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-…EPSS 1.2%7.7CVE-2021-44414Reolink rlc-410w firmware improper input validation vulnerabilityA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2019-11001), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.