Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application implements lock screen password logic entirely on the client side using JavaScript within an Electron resource file. Because the password is stored and returned via a modifiable JavaScript property(a.settingsManager.lockScreenPassword), an attacker can patch the return value to bypass authentication.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 21 Oct 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-290 | |
Metrics |
cvssV3_1
|
Tue, 21 Oct 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application implements lock screen password logic entirely on the client side using JavaScript within an Electron resource file. Because the password is stored and returned via a modifiable JavaScript property(a.settingsManager.lockScreenPassword), an attacker can patch the return value to bypass authentication. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-21T20:34:59.617Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-56800

Updated: 2025-10-21T20:34:55.209Z

Status : Awaiting Analysis
Published: 2025-10-21T19:21:22.780
Modified: 2025-10-21T21:15:38.113
Link: CVE-2025-56800

No data.

No data.