CVE-2025-55634

7.5

Reolink · Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime

An incorrect access control vulnerability in the Reolink Smart 2K+ Video Doorbell RTMP settings allows unauthenticated attackers to cause a Denial of Service via simultaneous stream pushes.

Executive summary

A critical access control flaw in the Reolink Smart 2K+ Video Doorbell allows unauthenticated remote attackers to crash the device through a Denial of Service attack.

Vulnerability

The vulnerability stems from improper access control in the RTMP server configuration, which permits unauthenticated attackers to initiate excessive ffmpeg based stream pushes. This resource exhaustion leads to a Denial of Service condition on the affected doorbell unit.

Business impact

The inability to maintain a functional video doorbell directly impacts physical security and surveillance capabilities. With a CVSS score of 7.5, this high severity issue represents a significant availability risk, as attackers can remotely disable the device, rendering it useless for monitoring or security alerts.

Remediation

Immediate Action: Restrict network access to the doorbell device by placing it on an isolated VLAN or using firewall rules to prevent unauthorized external access to the RTMP service.

Proactive Monitoring: Monitor the device for sudden service restarts or prolonged offline status, and review network logs for suspicious spikes in incoming RTMP connection requests.

Compensating Controls: Implement network-level rate limiting or an intrusion prevention system to detect and block abnormal quantities of concurrent stream initiation attempts directed at the doorbell.

Exploitation status

Public Exploit Available: Yes, a technical write-up containing attack details exists (referenced in the CVE record).

Analyst recommendation

Given the exposure of the RTMP service to unauthenticated users, this vulnerability poses a clear risk to operational continuity. Administrators should prioritize network segmentation to isolate the affected hardware from untrusted networks while awaiting a formal firmware patch from the vendor.

More Reolink CVEs

Sources