Medium severity6.2NVD Advisory· Published Jan 26, 2023· Updated Jun 17, 2026
CVE-2022-29843
CVE-2022-29843
Description
A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to execute code in the context of the root user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- cpe:2.3:o:westerndigital:my_cloud_dl2100_firmware:*:*:*:*:*:*:*:*Range: <5.26.119
- cpe:2.3:o:westerndigital:my_cloud_dl4100_firmware:*:*:*:*:*:*:*:*Range: <5.26.119
- cpe:2.3:o:westerndigital:my_cloud_ex2100_firmware:*:*:*:*:*:*:*:*Range: <5.26.119
- cpe:2.3:o:westerndigital:my_cloud_ex2_ultra_firmware:*:*:*:*:*:*:*:*Range: <5.26.119
- cpe:2.3:o:westerndigital:my_cloud_ex4100_firmware:*:*:*:*:*:*:*:*Range: <5.26.119
- cpe:2.3:o:westerndigital:my_cloud_mirror_g2_firmware:*:*:*:*:*:*:*:*Range: <5.26.119
- cpe:2.3:o:westerndigital:my_cloud_pr2100_firmware:*:*:*:*:*:*:*:*Range: <5.26.119
- cpe:2.3:o:westerndigital:my_cloud_pr4100_firmware:*:*:*:*:*:*:*:*Range: <5.26.119
- Range: <5.26.119
- Range: <5.26.119
- Western Digital/My Cloudv5Range: My Cloud OS 5
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.