// For flags

CVE-2020-25173

Reolink P2P Cameras

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An attacker with local network access can obtain a fixed cryptography key which may allow for further compromise of Reolink P2P cameras outside of local network access

Un atacante con acceso a la red local puede obtener una clave de criptografía fija que puede permitir un mayor compromiso de las cámaras P2P Reolink fuera del acceso a la red local

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-09-04 CVE Reserved
  • 2021-01-26 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-321: Use of Hard-coded Cryptographic Key
  • CWE-798: Use of Hard-coded Credentials
CAPEC
References (1)
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Reolink
Search vendor "Reolink"
Rln8-410 Firmware
Search vendor "Reolink" for product "Rln8-410 Firmware"
--
Affected
in Reolink
Search vendor "Reolink"
Rln8-410
Search vendor "Reolink" for product "Rln8-410"
--
Safe
Reolink
Search vendor "Reolink"
Rlc-422 Firmware
Search vendor "Reolink" for product "Rlc-422 Firmware"
--
Affected
in Reolink
Search vendor "Reolink"
Rlc-422
Search vendor "Reolink" for product "Rlc-422"
--
Safe
Reolink
Search vendor "Reolink"
Rlc-510a Firmware
Search vendor "Reolink" for product "Rlc-510a Firmware"
--
Affected
in Reolink
Search vendor "Reolink"
Rlc-510a
Search vendor "Reolink" for product "Rlc-510a"
--
Safe
Reolink
Search vendor "Reolink"
Rlc-423s Firmware
Search vendor "Reolink" for product "Rlc-423s Firmware"
--
Affected
in Reolink
Search vendor "Reolink"
Rlc-423s
Search vendor "Reolink" for product "Rlc-423s"
--
Safe
Reolink
Search vendor "Reolink"
Rlc-423 Firmware
Search vendor "Reolink" for product "Rlc-423 Firmware"
--
Affected
in Reolink
Search vendor "Reolink"
Rlc-423
Search vendor "Reolink" for product "Rlc-423"
--
Safe
Reolink
Search vendor "Reolink"
Rlc-410 Firmware
Search vendor "Reolink" for product "Rlc-410 Firmware"
--
Affected
in Reolink
Search vendor "Reolink"
Rlc-410
Search vendor "Reolink" for product "Rlc-410"
--
Safe
Reolink
Search vendor "Reolink"
Rlc-520a Firmware
Search vendor "Reolink" for product "Rlc-520a Firmware"
--
Affected
in Reolink
Search vendor "Reolink"
Rlc-520a
Search vendor "Reolink" for product "Rlc-520a"
--
Safe