Skip to main content
HIGH

CVE-2021-40412

CVSS v3

7.2

HIGH

EPSS Score

27.5 %

exploit probability, as of 2026-10-05

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [8] the devname variable, that has the value of the name parameter provided through the SetDevName API, is not validated properly. This would lead to an OS command injection.

Technical details

Published
2022-01-28

Frequently asked questions

What is CVE-2021-40412?

An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [8] the devname variable, that has the value of the name parameter provided through the SetDevName API, is not validated properly. This would lead to an OS command injection.

Is CVE-2021-40412 actively exploited?

Active exploitation of CVE-2021-40412 has not been confirmed. Its EPSS score was 27.5% on 2026-10-05, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-40412?

CVE-2021-40412 has a CVSS v3 base score of 7.2 (HIGH severity).

Is CVE-2021-40412 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key