CVE-2025-55629
Insecure permissions in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime – firmware v3.0.0.4662_2503122283 allow attackers to arbitrarily change other users’ passwords via manipulation of the userName value.
More information : https://relieved-knuckle-264.notion.site/Account-Takeover-Change-password-23c437003642806bb821fec983aedb9f?source=copy_link