← Vulnerability feed

Vulnerability record · CVE-2021-40407 · published 28 January 2022

CVE-2021-40407: Reolink RLC-410W camera DDNS domain OS command injection

Reolink · Rlc 410w Firmware

The Reolink RLC-410W firmware v3.0.0.136_20121102 fails to validate the ddns->domain value supplied through the SetDdns API, allowing OS command injection. Because the flaw sits in device network settings reachable over HTTP, a successful injection gives command execution on the camera. The record names only this single firmware version, so other builds are unconfirmed.

7.2 CVSS 3.1 High CISA KEV since 18 Dec 2024 EPSS 48% · top 1.2% CWE-78 · OS command injection
7.2CVSS 3.1 base score, v2 7.5
48%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->domain variable, that has the value of the domain parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection. An attacker can send an HTTP request to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw allows remote OS command execution and is in CISA KEV with high EPSS, but exploitation requires high privileges and the affected product may be end-of-life.

What it is

The Reolink RLC-410W firmware v3.0.0.136_20121102 fails to validate the ddns->domain value supplied through the SetDdns API, allowing OS command injection. Because the flaw sits in device network settings reachable over HTTP, a successful injection gives command execution on the camera. The record names only this single firmware version, so other builds are unconfirmed.

Impact

An attacker who can reach the SetDdns API gains arbitrary OS command execution on the camera, compromising confidentiality, integrity and availability of the device and anything it can reach.

Attack surface

Reached over the network via an HTTP request to the SetDdns API, with the DDNS domain parameter as the injection point. The CVSS vector requires high privileges (PR:H), so valid administrative access is needed; no user interaction is required.

Exploitation

CISA added this to KEV on 2024-12-18 with a 2025-01-08 remediation due date, and EPSS shows a 30-day probability of 0.47635 (98.8th percentile). Talos references are tagged Exploit, indicating public exploit detail exists; no ransomware campaign use is documented.

What to do

  • Apply the vendor firmware update for the RLC-410W if one is available; CISA notes the product may be end-of-life or end-of-service.
  • If no fix exists, discontinue use of the device as CISA recommends, or isolate it on a segmented network with no internet exposure.
  • Restrict access to the camera's HTTP management interface and SetDdns API to trusted administrative hosts only.
  • Change default administrative credentials and enforce strong unique passwords to limit the high-privilege access the flaw requires.
  • Monitor vendor and CISA guidance for an updated firmware or replacement model.

Detection

  • Review camera and upstream logs for HTTP requests to the SetDdns API containing shell metacharacters or unexpected domain values.
  • Alert on unexpected outbound connections or new processes on the camera or its network segment.
  • Audit administrative logins to the camera for unusual source addresses or times.
  • Inventory RLC-410W devices on the network and flag any still running firmware v3.0.0.136_20121102.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-40407 to the Known Exploited Vulnerabilities catalog on 18 December 2024 as "Reolink RLC-410W IP Camera OS Command Injection Vulnerability ". Required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable. Federal deadline 8 January 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-40407 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2019-11001Reolink IP cameras OS command injection via TestEmailReolink RLC-410W, C1 Pro, C2 Pro, RLC-422W and RLC-511W devices through firmware 1.0.227 allow an authenticated admin to inject OS commands through t…KEVEPSS 38%analysed9.8CVE-2022-21217Reolink rlc-410w firmware out-of-bounds write vulnerabilityAn out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted networ…EPSS 1.2%9.8CVE-2021-40408Reolink rlc-410w firmware os command injection vulnerabilityAn OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], bas…EPSS 3.7%9.8CVE-2021-40409Reolink rlc-410w firmware os command injection vulnerabilityAn OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], bas…EPSS 3.7%8.8CVE-2021-40416Reolink rlc-410w firmware improper access control vulnerabilityAn incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. Al…EPSS 0.87%8.2CVE-2022-21796Reolink rlc-410w firmware improper input validation vulnerabilityA memory corruption vulnerability exists in the netserver parse_command_list functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-craft…EPSS 1.1%7.7CVE-2021-44413Reolink rlc-410w firmware improper input validation vulnerabilityA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-…EPSS 1.2%7.7CVE-2021-44414Reolink rlc-410w firmware improper input validation vulnerabilityA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2021-40407), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.