Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker can leverage this vulnerability to decrypt access tokens and web session tokens stored inside the app via reverse engineering.
| Software | From | Fixed in |
|---|---|---|
| reolink / reolink | 4.54.0.4.20250526 | 4.54.0.4.20250526.x |