CVE Vulnerabilities

CVE-2025-55619

Use of Hard-coded Cryptographic Key

Published: Aug 22, 2025 | Modified: Aug 28, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker can leverage this vulnerability to decrypt access tokens and web session tokens stored inside the app via reverse engineering.

Weakness

The product uses a hard-coded, unchangeable cryptographic key.

Affected Software

NameVendorStart VersionEnd Version
ReolinkReolink4.54.0.4.20250526 (including)4.54.0.4.20250526 (including)

Potential Mitigations

References