shinyColumn/CVE-2025-56801

shinyColumn/CVE-2025-56801

Releases0
AES-CFB IV Generation Vulnerability in Reolink Desktop Application

CVE History

CVEPublishedCVSS v3CVSS v2
5.1 MEDIUM

The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data. NOTE: the Supplier's position is that material is not hardcoded and is instead randomly generated on each installation of the application.