Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8px6-9gmx-37g4

Опубликовано: 22 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker can leverage this vulnerability to decrypt access tokens and web session tokens stored inside the app via reverse engineering.

Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker can leverage this vulnerability to decrypt access tokens and web session tokens stored inside the app via reverse engineering.

EPSS

Процентиль: 26%
0.00093
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-321

Связанные уязвимости

CVSS3: 9.8
nvd
6 месяцев назад

Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker can leverage this vulnerability to decrypt access tokens and web session tokens stored inside the app via reverse engineering.

EPSS

Процентиль: 26%
0.00093
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-321