Root Shell Access Vulnerability in Reolink Video Doorbell WiFi
CVE-2025-60856

6.8MEDIUM

Key Information:

Vendor

Reolink

Vendor
CVE Published:
20 October 2025

What is CVE-2025-60856?

The Reolink Video Doorbell WiFi DB_566128M5MP_W has a significant vulnerability that allows an attacker to gain root shell access via an unsecured UART/serial console. This vulnerability is particularly concerning because an individual with physical access can connect to this exposed interface and execute arbitrary commands with root privileges, potentially compromising the device's integrity and security. Proper safeguards must be implemented to prevent unauthorized access and mitigate risks associated with this flaw.

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-60856 : Root Shell Access Vulnerability in Reolink Video Doorbell WiFi