Home

Description

The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data. NOTE: the Supplier's position is that material is not hardcoded and is instead randomly generated on each installation of the application.

PUBLISHED Reserved 2025-08-17 | Published 2025-10-21 | Updated 2025-10-22 | Assigner mitre

References

shinycolumn.notion.site/reolink-aes-iv

github.com/shinyColumn/CVE-2025-56801

cve.org (CVE-2025-56801)

nvd.nist.gov (CVE-2025-56801)

Download JSON