CVE Vulnerabilities

CVE-2025-55622

Public cloneable() Method Without Final ('Object Hijack')

Published: Aug 22, 2025 | Modified: Aug 28, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Reolink v4.54.0.4.20250526 was discovered to contain a task hijacking vulnerability due to inappropriate taskAffinity settings.

Weakness

A class has a cloneable() method that is not declared final, which allows an object to be created without calling the constructor. This can cause the object to be in an unexpected state.

Affected Software

Name Vendor Start Version End Version
Reolink Reolink 4.54.0.4.20250526 (including) 4.54.0.4.20250526 (including)

Potential Mitigations

References