Insufficient Firmware Update Validation in Reolink Video Doorbell
CVE-2025-60855

5.1MEDIUM

Key Information:

Vendor

Reolink

Vendor
CVE Published:
16 October 2025

What is CVE-2025-60855?

The Reolink Video Doorbell WiFi DB_566128M5MP_W is vulnerable due to its inadequate validation of firmware update signatures. This significant security flaw enables attackers to load and execute malicious firmware images, potentially giving them root privileges over the device. Consequently, unauthorized access can lead to exploitation and compromise of the device's functionalities. It is crucial for users to be aware of this vulnerability and consider necessary security measures, including the application of future firmware updates that address this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.