CVE-2020-25169
Estado: ModificadaAlta (7.5)—
The affected Reolink P2P products do not sufficiently protect data transferred between the local device and Reolink servers. This can allow an attacker to access sensitive information, such as camera feeds.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.99%
- Percentil entre todas las CVEs puntuadas: 61
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (7)
CWE
- CWE-319
- CWE-319
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-25169",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "Reolink",
"product": "RLC-4XX series",
"versions": [
{
"status": "affected",
"version": "All versions"
}
]
},
{
"vendor": "Reolink",
"product": "RLC-5XX series",
"versions": [
{
"status": "affected",
"version": "All versions"
}
]
},
{
"vendor": "Reolink",
"product": "RLN-X10 series",
"versions": [
{
"status": "affected",
"version": "All versions"
}
]
}
]
}
],
"published": "2021-01-26T18:15:43.037",
"references": [
{
"url": "https://us-cert.cisa.gov/ics/advisories/icsa-21-019-02",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://us-cert.cisa.gov/ics/advisories/icsa-21-019-02",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The affected Reolink P2P products do not sufficiently protect data transferred between the local device and Reolink servers. This can allow an attacker to access sensitive information, such as camera feeds."
},
{
"lang": "es",
"value": "Los productos P2P de Reolink afectados no protegen suficientemente los datos transferidos entre el dispositivo local y los servidores de Reolink. Esto puede permitir a un atacante acceder a información confidencial, tales como imágenes de cámaras"
}
],
"lastModified": "2026-06-17T03:06:30.190",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:reolink:rln8-410_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DA97CBF4-7E5C-4DF4-99C7-244BC3CC77DC"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:reolink:rln8-410:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4AE63907-9A5E-46D2-BCE3-41B2B1FD22F6"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:reolink:rlc-422_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EE43C3EF-3920-49B9-BB6B-9EA03DDFB954"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:reolink:rlc-422:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "097FC838-6BEB-4A6E-9ADA-B49F6D926561"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:reolink:rlc-510a_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4C4A48F1-AD16-4499-8D9B-28086287608D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:reolink:rlc-510a:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "03EA9726-66B7-4B33-A8F3-3421F762CF08"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:reolink:rlc-410_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "03CB154B-7116-45B8-875A-CC25991DB230"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:reolink:rlc-410:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8C158CF9-2697-40AF-9828-C64F3654B097"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:reolink:rlc-423s_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5593386-2933-4692-89C3-F663C83344A5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:reolink:rlc-423s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F9DFB155-051D-4EBD-8627-932C81A5027C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:reolink:rlc-423_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "940DC985-48CA-46E7-8AB0-713688D2CFA6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:reolink:rlc-423:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E37962D1-C747-4D28-897A-E41A841DE61D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:reolink:rlc-520a_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AE181027-4C23-4F48-A8A6-96C23382CD99"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:reolink:rlc-520a:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "242B396F-15EF-4A4C-AC20-AA7366E0892F"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}