Vulnerabilities > Westerndigital > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-01-13 CVE-2022-22988 Incorrect Permission Assignment for Critical Resource vulnerability in Westerndigital Edgerover 0.25
File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources.
network
low complexity
westerndigital CWE-732
critical
9.1
2022-01-13 CVE-2022-22989 Out-of-bounds Write vulnerability in Westerndigital MY Cloud OS
My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploited by unauthenticated attackers on the network.
network
low complexity
westerndigital CWE-787
critical
9.8
2020-10-29 CVE-2020-27744 OS Command Injection vulnerability in Westerndigital MY Cloud Firmware
An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114.
network
low complexity
westerndigital CWE-78
critical
10.0
2020-10-27 CVE-2020-27159 OS Command Injection vulnerability in Westerndigital MY Cloud Firmware
Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western Digital My Cloud NAS devices prior to 5.04.114
network
low complexity
westerndigital CWE-78
critical
10.0
2020-10-27 CVE-2020-27158 OS Command Injection vulnerability in Westerndigital MY Cloud Firmware
Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114.
network
low complexity
westerndigital CWE-78
critical
10.0
2020-10-27 CVE-2020-25765 OS Command Injection vulnerability in Westerndigital MY Cloud Firmware
Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western Digital My Cloud Devices prior to 5.4.1140.
network
low complexity
westerndigital CWE-78
critical
10.0
2019-06-19 CVE-2018-18472 OS Command Injection vulnerability in Westerndigital MY Book Live Firmware
Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter.
network
low complexity
westerndigital CWE-78
critical
10.0
2019-05-23 CVE-2019-9949 Link Following vulnerability in Westerndigital products
Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmware 2.31.183 are affected by a code execution (as root, starting from a low-privilege user session) vulnerability.
network
low complexity
westerndigital CWE-59
critical
9.0
2018-06-12 CVE-2018-1151 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Westerndigital TV Live HUB Firmware and TV Media Player Firmware
The web server on Western Digital TV Media Player 1.03.07 and TV Live Hub 3.12.13 allow unauthenticated remote attackers to execute arbitrary code or cause denial of service via crafted HTTP requests to toServerValue.cgi.
network
low complexity
westerndigital CWE-119
critical
10.0
2017-12-12 CVE-2017-17560 Improper Authentication vulnerability in Westerndigital MY Cloud Pr4100 Firmware 2.30.172
An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices.
network
low complexity
westerndigital CWE-287
critical
10.0