Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data. This command could be triggered by an attacker remotely to cause code execution and gain a reverse shell in Western Digital My Cloud OS 5 devices.This issue affects My Cloud OS 5: before 5.26.119.
2023-05-10T22:15:09.153
2024-11-21T06:59:47.723
Modified
CVSSv3.1: 8.0 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | westerndigital | my_cloud_os | < 5.26.119 | Yes |
Hardware | westerndigital | my_cloud | - | No |
Hardware | westerndigital | my_cloud_dl2100 | - | No |
Hardware | westerndigital | my_cloud_dl4100 | - | No |
Hardware | westerndigital | my_cloud_ex2_ultra | - | No |
Hardware | westerndigital | my_cloud_ex2100 | - | No |
Hardware | westerndigital | my_cloud_ex4100 | - | No |
Hardware | westerndigital | my_cloud_mirror_g2 | - | No |
Hardware | westerndigital | my_cloud_pr2100 | - | No |
Hardware | westerndigital | my_cloud_pr4100 | - | No |
Hardware | westerndigital | wd_cloud | - | No |