CVE Vulnerabilities

CVE-2025-55622

Public cloneable() Method Without Final ('Object Hijack')

Published: Aug 22, 2025 | Modified: Oct 02, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Reolink v4.54.0.4.20250526 was discovered to contain a task hijacking vulnerability due to inappropriate taskAffinity settings. NOTE: this is disputed by the Supplier because it is intentional behavior to ensure a predictable user experience.

Weakness

A class has a cloneable() method that is not declared final, which allows an object to be created without calling the constructor. This can cause the object to be in an unexpected state.

Affected Software

NameVendorStart VersionEnd Version
ReolinkReolink4.54.0.4.20250526 (including)4.54.0.4.20250526 (including)

Potential Mitigations

References