Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-40150 PoC — Reolink E1 Zoom Camera 安全漏洞

Source
Associated Vulnerability
Title:Reolink E1 Zoom Camera 安全漏洞 (CVE-2021-40150)
Description:Reolink E1 Zoom Camera是中国Reolink公司的一款双频 WiFi IP 摄像机。具有用于家庭安全的云台变焦功能,具有夜视、双向音频等功能。 Reolink E1 Zoom Camera 3.0.0.716 及之前存在安全漏洞,该漏洞源于应用配置缺少足够的保护。
Description
Reolink E1 Zoom camera through 3.0.0.716 is susceptible to information disclosure. The web server discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. An attacker with network-level access to the camera can can download the entire NGINX/FastCGI configurations by querying the /conf/nginx.conf or /conf/fastcgi.conf URI.
File Snapshot

id: CVE-2021-40150 info: name: Reolink E1 Zoom Camera <=3.0.0.716 - Information Disclosure auth ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.