CVE Vulnerabilities

CVE-2022-21236

Storage of File with Sensitive Data Under Web Root

Published: Jan 28, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.

Weakness

The product stores sensitive data under the web document root with insufficient access control, which might make it accessible to untrusted parties.

Affected Software

NameVendorStart VersionEnd Version
Rlc-410w_firmwareReolink3.0.0.136_20121102 (including)3.0.0.136_20121102 (including)

Potential Mitigations

References