VYPR
Unrated severityNVD Advisory· Published May 10, 2023· Updated Jan 24, 2025

Command Injection Vulnerability in Western Digital My Cloud devices

CVE-2022-29842

Description

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 devicesThis issue affects My Cloud OS 5: before 5.26.119.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A command injection vulnerability in Western Digital My Cloud OS 5 before 5.26.119 allows remote attackers to execute arbitrary commands as root.

Vulnerability

A command injection vulnerability exists in a CGI file of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119. The software fails to properly neutralize special elements in user-supplied input, allowing an attacker to inject arbitrary system commands. Affected models include My Cloud PR2100, PR4100, EX4100, EX2 Ultra, Mirror G2, DL2100, DL4100, EX2100, My Cloud, and WD Cloud [1].

Exploitation

An attacker can exploit this vulnerability remotely by sending a specially crafted request to the vulnerable CGI file. No authentication is required, and the attack does not require user interaction. The advisory notes that the command injection can be triggered remotely to achieve code execution [1].

Impact

Successful exploitation allows an attacker to execute arbitrary commands in the context of the root user, leading to full compromise of the device, including data disclosure, modification, and potential use as a pivot point for further attacks.

Mitigation

Western Digital released firmware version 5.26.119 on January 10, 2023, which addresses this vulnerability. Users are advised to update their devices promptly via the firmware update notification [1]. No workarounds are provided; updating to the fixed version is the only mitigation.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.