Command Injection Vulnerability in Western Digital My Cloud devices
Description
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 devicesThis issue affects My Cloud OS 5: before 5.26.119.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A command injection vulnerability in Western Digital My Cloud OS 5 before 5.26.119 allows remote attackers to execute arbitrary commands as root.
Vulnerability
A command injection vulnerability exists in a CGI file of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119. The software fails to properly neutralize special elements in user-supplied input, allowing an attacker to inject arbitrary system commands. Affected models include My Cloud PR2100, PR4100, EX4100, EX2 Ultra, Mirror G2, DL2100, DL4100, EX2100, My Cloud, and WD Cloud [1].
Exploitation
An attacker can exploit this vulnerability remotely by sending a specially crafted request to the vulnerable CGI file. No authentication is required, and the attack does not require user interaction. The advisory notes that the command injection can be triggered remotely to achieve code execution [1].
Impact
Successful exploitation allows an attacker to execute arbitrary commands in the context of the root user, leading to full compromise of the device, including data disclosure, modification, and potential use as a pivot point for further attacks.
Mitigation
Western Digital released firmware version 5.26.119 on January 10, 2023, which addresses this vulnerability. Users are advised to update their devices promptly via the firmware update notification [1]. No workarounds are provided; updating to the fixed version is the only mitigation.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <5.26.119
- Western Digital/My Cloud OS 5v5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.