CVE-2025-60858
7.5Reolink · Video Doorbell Wi-Fi (DB_566128M5MP_W)
Reolink Video Doorbell Wi-Fi devices store and transmit DDNS credentials in plaintext, potentially allowing unauthorized parties to intercept or extract sensitive authentication information.
Executive summary
A vulnerability in the Reolink Video Doorbell Wi-Fi allows for the plaintext exposure of DDNS credentials, presenting a significant risk of unauthorized access to network configuration settings.
Vulnerability
This vulnerability involves the insecure storage and transmission of sensitive DDNS credentials within configuration and update scripts. The vulnerability is unauthenticated, meaning an attacker does not require prior access to the device to potentially intercept this data.
Business impact
The exposure of DDNS credentials can lead to unauthorized remote access or manipulation of network services associated with the device. Given the CVSS score of 7.5, this high severity flaw could result in significant data compromise or the hijacking of doorbell functionality, potentially facilitating further network penetration.
Remediation
Immediate Action: Consult the official Reolink download center to identify if a firmware update addressing this credential exposure is available for your specific device model.
Proactive Monitoring: Review network traffic logs for unusual outbound connections or unauthorized access attempts directed toward the device management interface.
Compensating Controls: Isolate IoT devices on a dedicated VLAN and implement network monitoring or firewall rules to restrict traffic to known, trusted endpoints, thereby limiting the impact of potential credential theft.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a critical security oversight regarding the handling of sensitive credentials. Organizations and individuals using the affected Reolink hardware should prioritize checking for firmware updates and implement network-level segmentation to mitigate the risk of credential interception until a verified patch is applied.