CVE-2024-48644
MEDIUMReolink Duo 2 WiFi Camera v3.0.0.1889_23031701 - Info Disclosure
Title source: llmDescription
Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_23031701) allows remote attackers to determine valid user accounts via login attempts. This can lead to the enumeration of user accounts and potentially facilitate other attacks, such as brute-forcing of passwords. The vulnerability arises from the application responding differently to login attempts with valid and invalid usernames.
Exploits (1)
Scores
CVSS v3
5.3
EPSS
0.0158
EPSS Percentile
81.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-203
Status
published
Published
Oct 22, 2024
Tracked Since
Feb 18, 2026