Insecure Direct Object Reference in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell
CVE-2025-55626
5.3MEDIUM
What is CVE-2025-55626?
A vulnerability exists in the Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell that allows unauthorized users to exploit Insecure Direct Object Reference (IDOR). This flaw permits attackers to gain access to Admin-only settings, compromising the integrity of user sessions and enabling unauthorized manipulation of session storage.
