Skip to main content

Share story

Security

CVE-2026-57473: Use of Weak Credentials in Reolink Home Hub

Nozomi Networks Labs reported CVE-2026-57473 on June 26, 2026. The vulnerability, titled Use of Weak Credentials, is a CWE-1391 issue in the netclient and factory services of Reolink Home Hub. It stems from the possibility of brute-force cracking of the credentials in versions prior to v3.3.0.456_26031911, the advisory states. An adjacent attacker may intercept traffic and compromise credentials of associated cameras. The vulnerability carries a CVSS score of 5.8 based on the vector CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H. It affects Reolink Home Hub versions prior to v3.3.0.456_26031911. The solution is to update to at least version v3.3.0.456_26031911, which addresses the issue. The advisory credits Raffaele Bova at Nozomi Networks. The report appears on the Nozomi Networks Labs site.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Nozomi Networks Labs and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Infrastructure Capital
Infrastructure Capital

Nscale secures $3.36 billion in financing ahead of planned IPO

British AI data center developer Nscale said it secured $3.36 billion in convertible-note financing ahead of a planned US stock-market listing. The Third Point-led deal makes $2.36 billion available immediately, while a further $1...

Infrastructure Products
Infrastructure Products

Tower and Japan plan $4 billion optical chip expansion

Tower Semiconductor and Japan's government plan to invest a combined $4 billion in Japanese factories that make chips for optical connections, Tom's Hardware reports. Tower plans to contribute $3 billion and Japan's Ministry of Ec...

Capital AI
Capital AI

Enveda raises $311 million to advance AI-assisted drug candidates

Enveda has raised $311 million in Series E financing at a $2 billion valuation as it moves drug candidates found through its AI-assisted search of natural compounds into human testing. Catalio Capital Management led the round, wit...

Security Infrastructure
Security Infrastructure

Researchers find personal data exposed in around 16,000 Supabase databases

Security firm UpGuard found around 16,000 databases hosted by Supabase with some personal data exposed to the public web, TechCrunch reports. The accessible information included names, addresses and phone numbers; a smaller number...

Security Policy
Security Policy

CISA sets deadlines for agencies to address four exploited software flaws

CISA has added exploited vulnerabilities affecting WSO2 products, Adobe Commerce, Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities catalog. Federal agencies using the affected products must apply r...

AI Products
AI Products

S&P Global Energy opens governed data queries to customer AI agents

S&P Global Energy says it has built a way for customers' AI agents to query its structured energy data in natural language. Its domain experts organize datasets into focused Databricks Genie Agents, each with business definitions ...