CVE Explorer
CVE-2026-57473
A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibility of brute-force cracking the credentials. This issue could allow attackers on the same local network to intercept traffic between the Hub and associated cameras and compromise the credentials of connected cameras.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Home Hub","vendor":"Reolink","versions":[{"lessThan":"3.3.0.456_26031911","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:560c91154f45381a5226981384fbb23ab04c9bd2dbaca6d00fc9b52ac241fd55 · sha256:73e592289ba77f59… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"ADJACENT","baseScore":5.8,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImp…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:560c91154f45381a5226981384fbb23ab04c9bd2dbaca6d00fc9b52ac241fd55 · sha256:73e592289ba77f59… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-1391","description":"CWE-1391 Use of Weak Credentials","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:560c91154f45381a5226981384fbb23ab04c9bd2dbaca6d00fc9b52ac241fd55 · sha256:73e592289ba77f59… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["third-party-advisory"],"url":"https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-57473"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:560c91154f45381a5226981384fbb23ab04c9bd2dbaca6d00fc9b52ac241fd55 · sha256:73e592289ba77f59… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.