Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-38fr-2xrg-mwqm

Опубликовано: 21 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.1

Описание

The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data.

The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data.

EPSS

Процентиль: 4%
0.00142
Низкий

5.1 Medium

CVSS3

Дефекты

CWE-321

Связанные уязвимости

CVSS3: 5.1
nvd
11 месяцев назад

The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data. NOTE: the Supplier's position is that material is not hardcoded and is instead randomly generated on each installation of the application.

EPSS

Процентиль: 4%
0.00142
Низкий

5.1 Medium

CVSS3

Дефекты

CWE-321