CVE-2025-55621

An Insecure Direct Object Reference (IDOR) vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access and download other users' profile photos via a crafted URL. NOTE: this is disputed by the Supplier because it is intentional behavior; the photos are part of a social platform on which users expect to find one another.
Configurations

Configuration 1 (hide)

cpe:2.3:a:reolink:reolink:4.54.0.4.20250526:*:*:*:*:android:*:*

History

No history.

Information

Published : 2025-08-22 17:15

Updated : 2025-10-02 01:58


NVD link : CVE-2025-55621

Mitre link : CVE-2025-55621

CVE.ORG link : CVE-2025-55621


JSON object : View

Products Affected

reolink

  • reolink
CWE
CWE-639

Authorization Bypass Through User-Controlled Key