A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to build files with redirects and execute larger payloads. This issue affects My Cloud OS 5 devices: before 5.26.300.
2023-06-30T22:15:09.883
2024-11-21T07:45:28.480
Modified
CVSSv3.1: 6.0 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | westerndigital | my_cloud_os | < 5.26.300 | Yes |
Hardware | westerndigital | my_cloud | - | No |
Hardware | westerndigital | my_cloud_dl2100 | - | No |
Hardware | westerndigital | my_cloud_dl4100 | - | No |
Hardware | westerndigital | my_cloud_ex2_ultra | - | No |
Hardware | westerndigital | my_cloud_ex2100 | - | No |
Hardware | westerndigital | my_cloud_ex4100 | - | No |
Hardware | westerndigital | my_cloud_mirror_g2 | - | No |
Hardware | westerndigital | my_cloud_pr2100 | - | No |
Hardware | westerndigital | my_cloud_pr4100 | - | No |
Hardware | westerndigital | wd_cloud | - | No |