Authentication Bypass Vulnerability in Reolink Desktop Application
CVE-2025-56800
5.1MEDIUM
Key Information:
- Vendor
Reolink
- Vendor
- CVE Published:
- 21 October 2025
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2025-56800?
The Reolink desktop application version 8.18.12 has a vulnerability in its local authentication mechanism where the lock screen password logic is implemented on the client side using JavaScript. This creates a potential security risk, as the password can be stored and modified through a JavaScript property, allowing an attacker to bypass authentication processes. The situation is complicated by the supplier's claims that such a bypass would only be feasible if a local user intentionally alters their application instance.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
