LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-40407: Reolink RLC-410W IP Camera OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 18, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jan 8, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-40407 to its Known Exploited Vulnerabilities catalog on Dec 18, 2024, with a federal patch deadline of Jan 8, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.

CVE-2021-40407 is an authenticated OS command injection vulnerability affecting the Reolink RLC-410W IP camera. It resides in the device network settings functionality and allows an attacker who already has valid credentials to inject and execute operating-system commands on the camera. Because these cameras often sit on internal networks and may hold credentials or video streams, successful abuse can give an attacker a foothold for further movement or data access. Public detail is limited to the CISA summary; confirm exact impact and any available fixes against the vendor advisory.

The weakness is classified as CWE-78. CISA notes that the product may be end-of-life or end-of-service, so organizations still running the model should treat it as high priority for inventory and risk reduction.

How it works

OS command injection (CWE-78) occurs when an application passes unsanitized user-controlled input into a system shell or command interpreter. On the Reolink RLC-410W, the vulnerable surface is the authenticated network-settings interface. An attacker who can log in with legitimate credentials can supply crafted input that the camera interprets as shell commands rather than configuration data. Those commands then run with the privileges of the process handling the settings page. No unauthenticated remote path is described in the available facts; authentication is required. Exact parameter names, payload formats, or privilege levels are not published here and must be verified against the vendor advisory.

Am I affected? How to find it in your systems

The only model named is the Reolink RLC-410W IP camera. These devices typically appear on corporate or home networks as wired or wireless surveillance endpoints, often managed through a web UI, mobile app, or NVR. To inventory:

Because version ranges are not supplied in the facts, treat every RLC-410W as potentially vulnerable until the vendor advisory is checked. Telemetry signs of exploitation are not detailed publicly; look for unexpected process execution, new outbound connections, or configuration changes originating from the network-settings page after authenticated sessions. Correlate camera logs with authentication events and network flow data.

How to remediate

Apply any vendor-supplied update or firmware that addresses CVE-2021-40407 as soon as it is confirmed available. CISA states the product could be end-of-life or end-of-service; if no current mitigation exists, discontinue use of the device. After patching (or replacement):

Confirm the precise remediation steps and any residual risk statements against the vendor advisory before declaring systems clean.

If you can't patch immediately

When an immediate update or replacement is impossible, reduce exposure with compensating controls:

These measures lower risk but do not eliminate the underlying flaw; plan for permanent remediation or decommissioning as soon as feasible.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to broader network compromise and data exposure. Known ransomware use of CVE-2021-40407 is not documented. If you suspect the camera was abused, isolate it, preserve logs, and investigate for lateral movement. You can also run a free exposure scan of your email address against known breach data sets to check whether associated credentials have appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedReolink · RLC-410W IP Camera
WeaknessCWE-78
Added to CISA KEVDec 18, 2024
Federal patch deadlineJan 8, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities