Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 devicesThis issue affects My Cloud OS 5: before 5.26.119.
2023-05-10T21:15:08.867
2024-11-21T06:59:47.857
Modified
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? | 
|---|---|---|---|---|
| Operating System | westerndigital | my_cloud_os | < 5.26.119 | Yes | 
| Hardware | westerndigital | my_cloud | - | No | 
| Hardware | westerndigital | my_cloud_dl2100 | - | No | 
| Hardware | westerndigital | my_cloud_dl4100 | - | No | 
| Hardware | westerndigital | my_cloud_ex2_ultra | - | No | 
| Hardware | westerndigital | my_cloud_ex2100 | - | No | 
| Hardware | westerndigital | my_cloud_ex4100 | - | No | 
| Hardware | westerndigital | my_cloud_mirror_g2 | - | No | 
| Hardware | westerndigital | my_cloud_pr2100 | - | No | 
| Hardware | westerndigital | my_cloud_pr4100 | - | No | 
| Hardware | westerndigital | wd_cloud | - | No |