← Back to CVE List

CVE-2024-48644

Published: 2024-10-22T22:15Z
Last Modified: 2024-10-23T19:35Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_23031701) allows remote attackers to determine valid user accounts via login attempts. This can lead to the enumeration of user accounts and potentially facilitate other attacks, such as brute-forcing of passwords. The vulnerability arises from the application responding differently to login attempts with valid and invalid usernames. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt