We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Assigner | WDC PSIRT |
Reserved | 2023-01-06 |
Published | 2023-06-30 |
Updated | 2024-09-05 |
A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to build files with redirects and execute larger payloads. This issue affects My Cloud OS 5 devices: before 5.26.300.
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:H |
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Wil Gibbs and Arvind S Raj
https://www.westerndigital.com/support/product-security/wdc-23010-my-cloud-firmware-version-5-26-300