Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker can leverage this vulnerability to decrypt access tokens and web session tokens stored inside the app via reverse engineering.
https://nvd.nist.gov/vuln/detail/CVE-2020-25173
https://developer.android.com/reference/kotlin/androidx/security/crypto/EncryptedSharedPreferences