CVE Vulnerabilities

CVE-2025-55619

Use of Hard-coded Cryptographic Key

Published: Aug 22, 2025 | Modified: Aug 28, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker can leverage this vulnerability to decrypt access tokens and web session tokens stored inside the app via reverse engineering.

Weakness

The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.

Affected Software

Name Vendor Start Version End Version
Reolink Reolink 4.54.0.4.20250526 (including) 4.54.0.4.20250526 (including)

Potential Mitigations

References