Beveiligingsadvies

CVE-2025-56802

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-10-21 00:00:00
Laatst bijgewerkt 2025-10-22 13:22:33
Toegewezen door mitre
CVSS-score 5.1
Status PUBLISHED

Beschrijving

The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files allowing attackers with local access to decrypt sensitive application data stored in %APPDATA%. A different vulnerability than CVE-2025-56801. NOTE: the Supplier's position is that material is not hardcoded and is instead randomly generated on each installation of the application.