CVE-2025-55634

Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows unauthorized attackers to cause a Denial of Service (DoS) via initiating a large number of simultaneous ffmpeg-based stream pushes.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:reolink:smart_2k\+_plug-in_wi-fi_video_doorbell_with_chime_firmware:3.0.0.4662_2503122283:*:*:*:*:*:*:*
cpe:2.3:h:reolink:smart_2k\+_plug-in_wi-fi_video_doorbell_with_chime:-:*:*:*:*:*:*:*

History

21 Oct 2025, 13:57

Type Values Removed Values Added
CPE cpe:2.3:o:reolink:smart_2k\+_plug-in_wi-fi_video_doorbell_with_chime_firmware:3.0.0.4662_2503122283:*:*:*:*:*:*:*
cpe:2.3:h:reolink:smart_2k\+_plug-in_wi-fi_video_doorbell_with_chime:-:*:*:*:*:*:*:*
Summary
  • (es) El control de acceso incorrecto en la configuración del servidor RTMP de Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 permite que atacantes no autorizados provoquen una denegación de servicio (DoS) al iniciar una gran cantidad de envíos simultáneos de transmisiones basadas en ffmpeg.
First Time Reolink
Reolink smart 2k\+ Plug-in Wi-fi Video Doorbell With Chime Firmware
Reolink smart 2k\+ Plug-in Wi-fi Video Doorbell With Chime
References () https://cwe.mitre.org/data/definitions/306.html - () https://cwe.mitre.org/data/definitions/306.html - Technical Description
References () https://cwe.mitre.org/data/definitions/400.html - () https://cwe.mitre.org/data/definitions/400.html - Technical Description
References () https://relieved-knuckle-264.notion.site/RTMP-Injection-DoS-through-Unauthenticated-Stream-Publish-23c437003642800297c8c128b6117885?pvs=74 - () https://relieved-knuckle-264.notion.site/RTMP-Injection-DoS-through-Unauthenticated-Stream-Publish-23c437003642800297c8c128b6117885?pvs=74 - Exploit, Third Party Advisory

22 Aug 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-400

22 Aug 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-22 17:15

Updated : 2025-10-21 13:57


NVD link : CVE-2025-55634

Mitre link : CVE-2025-55634

CVE.ORG link : CVE-2025-55634


JSON object : View

Products Affected

reolink

  • smart_2k\+_plug-in_wi-fi_video_doorbell_with_chime
  • smart_2k\+_plug-in_wi-fi_video_doorbell_with_chime_firmware
CWE
CWE-400

Uncontrolled Resource Consumption