Improper access control in WD My Book Live and WD My Book Live Duo - CVE-2021-35941
Published: June 30, 2021
WD My Book Live
WD My Book Live Duo
Western Digital
Description
The vulnerability allows a remote attacker to delete all data on the system.
The vulnerability exists due to improper access restrictions to the administrator API. A remote non-authenticated attacker can send a specially crafted HTTP request to the exposed API and perform a system factory restore, deleting all data on the NAS device.
Note, the vulnerability is being actively exploited in the wild along with vulnerability #VU15460.