Hardcoded Encryption Key Vulnerability in Reolink Mobile Application
CVE-2025-55619
9.8CRITICAL
What is CVE-2025-55619?
The Reolink Mobile Application version 4.54.0.4.20250526 is susceptible to a vulnerability where a hardcoded encryption key and initialization vector are used. This flaw enables potential attackers to reverse engineer the app, allowing them to decrypt sensitive access tokens and web session tokens stored within the application. Such exposure can lead to unauthorized access and compromise of user accounts. It is crucial for users to be aware of this vulnerability and for the vendor to implement security enhancements to protect user data.
