Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-38fr-2xrg-mwqm

Опубликовано: 21 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.1

Описание

The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data.

The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data.

EPSS

Процентиль: 6%
0.00023
Низкий

5.1 Medium

CVSS3

Дефекты

CWE-321

Связанные уязвимости

CVSS3: 5.1
nvd
4 месяца назад

The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data. NOTE: the Supplier's position is that material is not hardcoded and is instead randomly generated on each installation of the application.

EPSS

Процентиль: 6%
0.00023
Низкий

5.1 Medium

CVSS3

Дефекты

CWE-321