CVE-2025-55625

An open redirect vulnerability in Reolink v4.54.0.4.20250526 allows attackers to redirect users to a malicious site via a crafted URL. NOTE: this is disputed by the Supplier because it is intentional behavior that supports redirection to Alexa URLs, which are not guaranteed to remain at the same domain indefinitely.
Configurations

Configuration 1 (hide)

cpe:2.3:a:reolink:reolink:4.54.0.4.20250526:*:*:*:*:android:*:*

History

01 Sep 2025, 21:15

Type Values Removed Values Added
Summary (en) An open redirect vulnerability in Reolink v4.54.0.4.20250526 allows attackers to redirect users to a malicious site via a crafted URL. (en) An open redirect vulnerability in Reolink v4.54.0.4.20250526 allows attackers to redirect users to a malicious site via a crafted URL. NOTE: this is disputed by the Supplier because it is intentional behavior that supports redirection to Alexa URLs, which are not guaranteed to remain at the same domain indefinitely.

28 Aug 2025, 13:46

Type Values Removed Values Added
First Time Reolink reolink
Reolink
CPE cpe:2.3:a:reolink:reolink:4.54.0.4.20250526:*:*:*:*:android:*:*
Summary
  • (es) Una vulnerabilidad de redirección abierta en Reolink v4.54.0.4.20250526 permite a los atacantes redirigir a los usuarios a un sitio malicioso a través de una URL manipulada.
References () https://cwe.mitre.org/data/definitions/601.html - () https://cwe.mitre.org/data/definitions/601.html - Third Party Advisory
References () https://relieved-knuckle-264.notion.site/Reolink-Deeplink-Redirect-21b437003642804a865af2fb02942f66 - () https://relieved-knuckle-264.notion.site/Reolink-Deeplink-Redirect-21b437003642804a865af2fb02942f66 - Exploit, Third Party Advisory

22 Aug 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-601

22 Aug 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-22 17:15

Updated : 2025-09-01 21:15


NVD link : CVE-2025-55625

Mitre link : CVE-2025-55625

CVE.ORG link : CVE-2025-55625


JSON object : View

Products Affected

reolink

  • reolink
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')