OS Command Injection vulnerability in Western Digital My Cloud devices
Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data. This command could be triggered by an attacker remotely to cause code execution and gain a reverse shell in Western Digital My Cloud OS 5 devices.This issue affects My Cloud OS 5: before 5.26.119.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An OS command injection in My Cloud OS 5 allows unauthenticated remote attackers to execute arbitrary commands as root via a crafted request to a vulnerable CGI endpoint.
Vulnerability
A command injection vulnerability (CWE-78) exists in Western Digital My Cloud OS 5 devices prior to version 5.26.119. The flaw resides in a CGI script that reads files from a privileged location and constructs a system command without sanitizing the read data. An attacker can exploit this by sending a specially crafted request to the vulnerable endpoint, leading to arbitrary command execution as root.
Exploitation
No authentication is required. An attacker with network access to the device can trigger the vulnerable command path by sending a malicious HTTP request. The request causes the CGI script to read attacker-controlled data from a privileged file and then pass that data directly into a system command without sanitization, resulting in command execution. No user interaction is needed.
Impact
Successful exploitation allows an attacker to execute arbitrary operating system commands with root privileges. This can lead to full compromise of the device, including data exfiltration, installation of persistent backdoors, and potentially using the device as a pivot point for further attacks on the local network.
Mitigation
Western Digital released firmware version 5.26.119 on January 10, 2023, which fixes this vulnerability. All affected My Cloud OS 5 models (PR2100, PR4100, EX4100, EX2 Ultra, Mirror G2, DL2100, DL4100, EX2100, My Cloud, and WD Cloud) should be updated to this version promptly. No workarounds are documented; updating the firmware is the recommended mitigation [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <5.26.119
- Western Digital/My Cloud OS 5v5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.