CVE Tools

Reolink

104 CVEs tracked since 2021. Since Jan 2021, 1 of them reached CISA KEV.

Reolink CVEs per month

Jan 2021 to Oct 2025. Point at a month, or focus the strip and use the arrow keys.
Reolink CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-0120
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01791
2022-02null or fewer
2022-03null or fewer
2022-0480
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08100
2025-09null or fewer
2025-1050

Products

The products that kept showing up in Reolink's monthly top three, with their CVEs summed over those months.

  1. Rlc-410w Firmware872 months
  2. Reolink112 months
  3. Reolink Rlc-410w91 month
  4. Rlc-410w81 month
  5. Smart 2k\+ Plug-in Wi-fi Video Doorbell With Chime Firmware31 month
  6. Reolink App21 month
  7. Rlc-410 Firmware21 month
  8. Rlc-422 Firmware21 month
  9. Rlc-423 Firmware21 month
  10. Reolink Wifi11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Reolink.

  1. CVE-2026-57473A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibility of brute-force cracking the credentials. This issue c...—
  2. CVE-2025-56799Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted folder name. NOTE: this is disputed by the Supplier because a ...6.5
  3. CVE-2025-56802The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files allowing attackers with local access to decrypt sensitive application data s...5.1
  4. CVE-2025-56801The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application e...5.1
  5. CVE-2025-56800Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application implements lock screen password logic entirely on the client side using JavaScrip...5.1
  6. CVE-2025-60856Reolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attacker with physical access can connect to the exposed interface and execute arbi...6.8
  7. CVE-2025-55625An open redirect vulnerability in Reolink v4.54.0.4.20250526 allows attackers to redirect users to a malicious site via a crafted URL. NOTE: this is disputed by the Supplier because it is intention...6.3
  8. CVE-2025-55624An intent redirection vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access internal functions or access non-public components.5.3
  9. CVE-2025-55622Reolink v4.54.0.4.20250526 was discovered to contain a task hijacking vulnerability due to inappropriate taskAffinity settings. NOTE: this is disputed by the Supplier because it is intentional beha...6.5
  10. CVE-2025-55630A discrepancy in the error message returned by the login function of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 when entering the wrong username and...7.3
  11. CVE-2025-55634Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows unauthorized attackers to cause a Denial o...7.5
  12. CVE-2025-55623An issue in the lock screen component of Reolink v4.54.0.4.20250526 allows attackers to bypass authentication via using an ADB (Android Debug Bridge).5.4
  13. CVE-2025-55620A cross-site scripting (XSS) vulnerability in the valuateJavascript() function of Reolink v4.54.0.4.20250526 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.6.1
  14. CVE-2025-55637Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to contain a command injection vulnerability via the setddns_pip_system() function.9.8
  15. CVE-2025-55621An Insecure Direct Object Reference (IDOR) vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access and download other users' profile photos via a crafted URL. NOTE: this...6.5

The record

Peak rank
#8 in Jan 2022
Busiest month shown
Jan 2022, 79 CVEs
Months with a KEV entry
1 since Jan 2021
Monthly snapshots
5 since 2021
Reolink's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store