User Enumeration Flaw in Reolink Smart 2K+ Video Doorbell
CVE-2025-55630

7.3HIGH

Key Information:

Vendor

Reolink

Vendor
CVE Published:
22 August 2025

What is CVE-2025-55630?

The Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell exhibits a security flaw in its login function, where an inconsistency in the error messages can be exploited by malicious actors. When incorrect login credentials are submitted, the device may reveal whether a specific username exists in the system through varied error responses. This facilitates unauthorized users to enumerate valid accounts, posing significant risks to user privacy and security. It is crucial for users of this device to be aware of this vulnerability and take appropriate measures to secure their accounts.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.