CVE-2025-55637

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
22/08/2025
Last modified:
21/10/2025

Description

Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to contain a command injection vulnerability via the setddns_pip_system() function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:reolink:smart_2k\+_plug-in_wi-fi_video_doorbell_with_chime_firmware:3.0.0.4662_2503122283:*:*:*:*:*:*:*
cpe:2.3:h:reolink:smart_2k\+_plug-in_wi-fi_video_doorbell_with_chime:-:*:*:*:*:*:*:*