Command injection in WD My Book Live - CVE-2018-18472

 

Command injection in WD My Book Live - CVE-2018-18472

Published: October 22, 2018 / Updated: June 30, 2021


Vulnerability identifier: #VU15460
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-18472
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary commands on the target system.

The weakness exists in the language change and modify functionality in the REST API. A remote attacker can send a specially crafted request to inject and execute arbitrary commands with root privileges.

Note, the vulnerability is being actively exploited in the wild.



Affected software

WD My Book Live

How to mitigate CVE-2018-18472

Cybersecurity Help is currently unaware of any solutions addressing the vulnerability.


External References

Related Security Bulletins