VYPR
Vendor

Westerndigital

Products
139
CVEs
97
Across products
274
Status
Private

Products

139
View all 139 products →

Recent CVEs

97
View all 97 CVEs →
  • CVE-2018-17153CriSep 18, 2018
    risk 0.74cvss 9.8epss 0.87

    It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authenticate as an admin user without needing to provide a password, thereby gaining…

  • CVE-2016-10108CriJan 3, 2017
    risk 0.74cvss 9.8epss 0.97

    Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg parameter in the POST data.

  • CVE-2017-17560CriDec 12, 2017
    risk 0.73cvss 9.8epss 0.73

    An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload functionality that is accessible without authentication and can be used to place a file anywhere on…

  • CVE-2019-16399CriSep 18, 2019
    risk 0.67cvss 9.8epss 0.07

    Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker can easily enable SSH from /admin/system_advanced.php?lang=en and login with the default root…

  • CVE-2018-18472CriJun 19, 2019
    risk 0.66cvss 9.8epss 0.30

    Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter. It can be triggered by anyone who knows the IP address of the affected device,…

  • CVE-2023-22814CriJul 1, 2023
    risk 0.65cvss 10.0epss 0.01

    An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack. This issue affects My Cloud OS 5 devices: before 5.26.202.

  • CVE-2022-36331CriJun 12, 2023
    risk 0.65cvss 10.0epss 0.01

    Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and…

  • CVE-2022-22995CriMar 25, 2022
    risk 0.65cvss 10.0epss 0.03

    The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.

  • CVE-2016-10107CriJan 3, 2017
    risk 0.65cvss 9.8epss 0.11

    Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a modified Cookie header.

  • CVE-2022-29842CriMay 10, 2023
    risk 0.64cvss 9.8epss 0.02

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 devicesThis issue affects My…

  • CVE-2021-36226CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.

  • CVE-2021-36224CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Western Digital My Cloud devices before OS5 have a nobody account with a blank password.

  • CVE-2022-22989CriJan 13, 2022
    risk 0.64cvss 9.8epss 0.01

    My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploited by unauthenticated attackers on the network. Addressed the vulnerability by adding defenses against stack overflow issues.

  • CVE-2020-29563CriDec 12, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to gain access to the device.

  • CVE-2020-28971CriDec 1, 2020
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths.

  • CVE-2020-28970CriDec 1, 2020
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie. (In addition, an upload endpoint could then be used by…

  • CVE-2020-28940CriDec 1, 2020
    risk 0.64cvss 9.8epss 0.04

    On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unauthenticated user to execute privileged commands on the device.

  • CVE-2020-27744CriOct 29, 2020
    risk 0.64cvss 9.8epss 0.06

    An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with resultant escalation of privileges.

  • CVE-2020-27160CriOct 27, 2020
    risk 0.64cvss 9.8epss 0.05

    Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114 (issue 3 of 3).

  • CVE-2020-27159CriOct 27, 2020
    risk 0.64cvss 9.8epss 0.06

    Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western Digital My Cloud NAS devices prior to 5.04.114