CVE-2025-55625

MEDIUM

Reolink v4.54.0.4.20250526 - Open Redirect

Title source: llm
STIX 2.1

Description

An open redirect vulnerability in Reolink v4.54.0.4.20250526 allows attackers to redirect users to a malicious site via a crafted URL. NOTE: this is disputed by the Supplier because it is intentional behavior that supports redirection to Alexa URLs, which are not guaranteed to remain at the same domain indefinitely.

Scores

CVSS v3 6.3
EPSS 0.0005
EPSS Percentile 15.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (1)
reolink/reolink 4.54.0.4.20250526
Published Aug 22, 2025
Tracked Since Feb 18, 2026