CVE-2022-21236
28.01.2022, 20:15
An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.Enginsight
Vendor | Product | Version |
---|---|---|
reolink | rlc-410w_firmware | 3.0.0.136_20121102:_20121102 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-219 - Storage of File with Sensitive Data Under Web RootThe application stores sensitive data under the web document root with insufficient access control, which might make it accessible to untrusted parties.
- CWE-552 - Files or Directories Accessible to External PartiesThe product makes files or directories accessible to unauthorized actors, even though they should not be.