CVE-2025-55631
7.5Reolink · Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime
Reolink Smart 2K+ Wi-Fi Video Doorbell firmware manages sessions globally rather than per account, which may lead to a Denial of Service through resource exhaustion.
Executive summary
A vulnerability in the session management architecture of the Reolink Smart 2K+ Video Doorbell firmware poses a risk of system-wide Denial of Service via resource exhaustion.
Vulnerability
The device performs session management on a system-wide basis rather than isolating sessions by account, allowing an unauthenticated attacker to exhaust device resources.
Business impact
The primary impact is the potential for service disruption, as the device becomes unresponsive due to resource exhaustion. While the CVSS score is 7.5, the actual risk to business operations is limited to the availability of the specific video doorbell unit, potentially impacting physical security monitoring capabilities.
Remediation
Immediate Action: Monitor official Reolink support channels for firmware updates that address session management limitations.
Proactive Monitoring: Review device logs for unusual spikes in connection attempts or sudden drops in device availability that could indicate an attempted resource exhaustion attack.
Compensating Controls: Ensure the device is isolated on a restricted management VLAN to limit exposure to untrusted network traffic.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit or weaponized code available in the provided data.
Analyst recommendation
Given the availability of a proof-of-concept, administrators should prioritize network segmentation for these devices. Users should maintain communication with the vendor to determine if future firmware iterations will introduce more granular session controls to mitigate this risk.