CVE-2025-55625
MEDIUM 6.3EPSS 0.2%
An open redirect vulnerability in Reolink v4.54.0.4.20250526 allows attackers to redirect users to a malicious site via a crafted URL. NOTE: this is disputed by the Supplier because it is intentional behavior that supports redirection to Alexa URLs, which are not guaranteed to remain at the same domain indefinitely.
- CVSS v3.1
- 6.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L - EPSS
- 0.23% chance of exploitation in the next 30 days, 14th percentile
- Published
- 2025-08-22
- Updated
- 2025-09-11