CVE-2025-60855
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
16/10/2025
Last modified:
21/10/2025
Description
Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows attackers to load malicious firmware images, resulting in arbitrary code execution with root privileges. NOTE: this is disputed by the Supplier because the integrity of updates is instead assured via a "private encryption algorithm" and other "tamper-proof verification."
Impact
Base Score 3.x
5.10
Severity 3.x
MEDIUM



