Back

CRITICAL

Command Injection Remote Code Execution vulnerability on Western Digital My Cloud devices.

Published Jan 28, 2022

Description

A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individual arguments to shell functions coming from user input.

Affected products

Remediation

Vendor solution

Update your My Cloud device to firmware version 5.19.117.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WDC PSIRT
Published Jan 28, 2022
Updated Aug 3, 2024
Reserved Jan 10, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a