Vulnerabilities > Westerndigital
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-09-30 | CVE-2019-13466 | Use of Hard-coded Credentials vulnerability in multiple products Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control. | 7.5 |
2019-09-18 | CVE-2019-16399 | Use of Hard-coded Credentials vulnerability in Westerndigital WD MY Book Firmware Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. | 9.8 |
2019-06-19 | CVE-2018-18472 | OS Command Injection vulnerability in Westerndigital MY Book Live Firmware Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter. | 9.8 |
2019-05-23 | CVE-2019-9949 | Link Following vulnerability in Westerndigital products Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmware 2.31.183 are affected by a code execution (as root, starting from a low-privilege user session) vulnerability. | 8.8 |
2019-04-24 | CVE-2019-9950 | Weak Password Requirements vulnerability in Westerndigital products Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an authentication bypass vulnerability. | 9.8 |
2018-10-09 | CVE-2018-7928 | Unspecified vulnerability in Westerndigital MY Cloud There is a security vulnerability which could lead to Factory Reset Protection (FRP) bypass in the MyCloud APP with the versions before 8.1.2.303 installed on some Huawei smart phones. low complexity westerndigital | 4.6 |
2018-06-12 | CVE-2018-1151 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Westerndigital TV Live HUB Firmware and TV Media Player Firmware The web server on Western Digital TV Media Player 1.03.07 and TV Live Hub 3.12.13 allow unauthenticated remote attackers to execute arbitrary code or cause denial of service via crafted HTTP requests to toServerValue.cgi. | 9.8 |
2018-03-30 | CVE-2018-9148 | Improper Authentication vulnerability in Westerndigital MY Cloud Firmware 04.05.00320 Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass authentication by listing a directory. | 9.8 |
2017-12-12 | CVE-2017-17560 | Improper Authentication vulnerability in Westerndigital MY Cloud Pr4100 Firmware 2.30.172 An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. | 9.8 |