CVE-2022-21236
An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 1.76%
- CWE
- CWE-219
- Published
- 2022-01-28
- Last modified
- 2026-03-13
Affected products
- n/a n/a
Weakness type
Related vulnerabilities
- CVE-2024-56159 — Server source code is exposed to the public if sourcemaps are enabled
- CVE-2024-39776 — Avtec Outpost Storage of File with Sensitive Data Under Web Root
- CVE-2023-39467 — Triangle MicroWorks SCADA Data Gateway certificate Information Disclosure Vulnerability
- CVE-2022-36306 — An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web...