Reolink v4.54.0.4.20250526 was discovered to contain a...
Critical severity
Unreviewed
Published
Aug 22, 2025
to the GitHub Advisory Database
•
Updated Aug 26, 2025
Description
Published by the National Vulnerability Database
Aug 22, 2025
Published to the GitHub Advisory Database
Aug 22, 2025
Last updated
Aug 26, 2025
Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker can leverage this vulnerability to decrypt access tokens and web session tokens stored inside the app via reverse engineering.
References