CVE-2018-18472
19.06.2019, 16:15
Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter. It can be triggered by anyone who knows the IP address of the affected device, as exploited in the wild in June 2021 for factory reset commands,
| Vendor | Product | Version |
|---|---|---|
| westerndigital | my_book_live_firmware | * |
𝑥
= Vulnerable software versions
References