PoC Index

CVE-2025-55625

MEDIUM 6.3EPSS 0.2%

An open redirect vulnerability in Reolink v4.54.0.4.20250526 allows attackers to redirect users to a malicious site via a crafted URL. NOTE: this is disputed by the Supplier because it is intentional behavior that supports redirection to Alexa URLs, which are not guaranteed to remain at the same domain indefinitely.

CVSS v3.1
6.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
EPSS
0.23% chance of exploitation in the next 30 days, 14th percentile
Published
2025-08-22
Updated
2025-09-11

Proof-of-concept exploits (1)

References

Related