VYPR
Unrated severityNVD Advisory· Published Jan 25, 2023· Updated Apr 4, 2025

Western Digital My Cloud OS 5 devices Command Injection Vulnerability

CVE-2022-29843

Description

A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to execute code in the context of the root user.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Western Digital My Cloud OS 5 devices before firmware 5.26.119 are vulnerable to command injection in the DDNS configuration, allowing root-level remote code execution.

Vulnerability

A command injection vulnerability exists in the DDNS service configuration of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119. The vulnerability allows an attacker to inject arbitrary system commands through the DDNS configuration functionality. Affected models include My Cloud PR2100, PR4100, EX4100, EX2 Ultra, Mirror G2, DL2100, DL4100, EX2100, My Cloud, and WD Cloud [1].

Exploitation

An attacker can exploit this vulnerability by sending specially crafted requests to the DDNS configuration endpoint of the device. No authentication is required to reach the vulnerable functionality, making it remotely exploitable over the network [1].

Impact

Successful exploitation enables the attacker to execute arbitrary commands in the context of the root user, resulting in full compromise of the device, including data access, further propagation, and potential persistence [1].

Mitigation

The vulnerability is fixed in My Cloud OS 5 firmware version 5.26.119, published on January 10, 2023 [1]. Users are advised to update their devices to this or later firmware versions. No workaround is available; updating is the only mitigation.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.