CVE-2025-60855

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
16/10/2025
Last modified:
21/10/2025

Description

Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows attackers to load malicious firmware images, resulting in arbitrary code execution with root privileges. NOTE: this is disputed by the Supplier because the integrity of updates is instead assured via a "private encryption algorithm" and other "tamper-proof verification."