Command injection in WD My Book Live - CVE-2018-18472
Published: October 22, 2018 / Updated: June 30, 2021
WD My Book Live
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The weakness exists in the language change and modify functionality in the REST API. A remote attacker can send a specially crafted request to inject and execute arbitrary commands with root privileges.
Note, the vulnerability is being actively exploited in the wild.