Vulnerability record · CVE-2021-40407 · published 28 January 2022
CVE-2021-40407: Reolink RLC-410W camera DDNS domain OS command injection
Reolink · Rlc 410w Firmware
The Reolink RLC-410W firmware v3.0.0.136_20121102 fails to validate the ddns->domain value supplied through the SetDdns API, allowing OS command injection. Because the flaw sits in device network settings reachable over HTTP, a successful injection gives command execution on the camera. The record names only this single firmware version, so other builds are unconfirmed.
Description
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->domain variable, that has the value of the domain parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection. An attacker can send an HTTP request to trigger this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows remote OS command execution and is in CISA KEV with high EPSS, but exploitation requires high privileges and the affected product may be end-of-life.
What it is
The Reolink RLC-410W firmware v3.0.0.136_20121102 fails to validate the ddns->domain value supplied through the SetDdns API, allowing OS command injection. Because the flaw sits in device network settings reachable over HTTP, a successful injection gives command execution on the camera. The record names only this single firmware version, so other builds are unconfirmed.
Impact
An attacker who can reach the SetDdns API gains arbitrary OS command execution on the camera, compromising confidentiality, integrity and availability of the device and anything it can reach.
Attack surface
Reached over the network via an HTTP request to the SetDdns API, with the DDNS domain parameter as the injection point. The CVSS vector requires high privileges (PR:H), so valid administrative access is needed; no user interaction is required.
Exploitation
CISA added this to KEV on 2024-12-18 with a 2025-01-08 remediation due date, and EPSS shows a 30-day probability of 0.47635 (98.8th percentile). Talos references are tagged Exploit, indicating public exploit detail exists; no ransomware campaign use is documented.
What to do
- Apply the vendor firmware update for the RLC-410W if one is available; CISA notes the product may be end-of-life or end-of-service.
- If no fix exists, discontinue use of the device as CISA recommends, or isolate it on a segmented network with no internet exposure.
- Restrict access to the camera's HTTP management interface and SetDdns API to trusted administrative hosts only.
- Change default administrative credentials and enforce strong unique passwords to limit the high-privilege access the flaw requires.
- Monitor vendor and CISA guidance for an updated firmware or replacement model.
Detection
- Review camera and upstream logs for HTTP requests to the SetDdns API containing shell metacharacters or unexpected domain values.
- Alert on unexpected outbound connections or new processes on the camera or its network segment.
- Audit administrative logins to the camera for unusual source addresses or times.
- Inventory RLC-410W devices on the network and flag any still running firmware v3.0.0.136_20121102.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-40407 to the Known Exploited Vulnerabilities catalog on 18 December 2024 as "Reolink RLC-410W IP Camera OS Command Injection Vulnerability ". Required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable. Federal deadline 8 January 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2021-1424 | ExploitThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2021-1424 | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40407 | US Government Resource |
Track CVE-2021-40407 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-40407), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.