Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 devicesThis issue affects My Cloud OS 5: before 5.26.119.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWesterndigital My Cloud
HWWesterndigitalall versionsWesterndigital My Cloud Dl2100
HWWesterndigitalall versionsWesterndigital My Cloud Dl4100
HWWesterndigitalall versionsWesterndigital My Cloud Ex2100
HWWesterndigitalall versionsWesterndigital My Cloud Ex2 Ultra
HWWesterndigitalall versionsWesterndigital My Cloud Ex4100
HWWesterndigitalall versionsWesterndigital My Cloud Mirror G2
HWWesterndigitalall versionsWesterndigital My Cloud Os
OSWesterndigital5.02.104 – 5.26.119 (excl.)Westerndigital My Cloud Pr2100
HWWesterndigitalall versionsWesterndigital My Cloud Pr4100
HWWesterndigitalall versionsWesterndigital Wd Cloud
HWWesterndigitalall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2023-22814CRITICAL10.0PL ✓same product
Pominięcie uwierzytelniania przez spoofing tokenów w Western Digital My Cloud OS 5
CVE-2022-36331CRITICAL10.0PL ✓same product
Podatność na atak impersonacji w urządzeniach Western Digital My Cloud
CVE-2021-36226CRITICAL9.8PL ✓same product
Western Digital My Cloud — brak weryfikacji podpisu kryptograficznego firmware
CVE-2021-36224CRITICAL9.8PL ✓same product
Western Digital My Cloud — wbudowane konto 'nobody' z pustym hasłem
CVE-2022-22995CRITICAL10.0PL ✓same product
RCE w Western Digital My Cloud — zapis dowolnych plików przez SMB i AFP