Vulnerabilities (CVE)

Filtered by vendor Westerndigital Subscribe
Filtered by product My Book Live
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-18472 1 Westerndigital 2 My Book Live, My Book Live Firmware 2023-12-10 10.0 HIGH 9.8 CRITICAL
Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter. It can be triggered by anyone who knows the IP address of the affected device, as exploited in the wild in June 2021 for factory reset commands,