Arbitrary file upload in Western Digital products - CVE-2022-22995

 

Arbitrary file upload in Western Digital products - CVE-2022-22995

Published: March 25, 2022 / Updated: July 18, 2026


Vulnerability identifier: #VU61623
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22995
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to insufficient validation of file during file upload within the combination of primitives offered by SMB and AFP in their default configuration. A remote attacker can upload a malicious file and execute it on the server.


Affected software

My Cloud PR2100
My Cloud PR4100
My Cloud EX4100
My Cloud EX2 Ultra
My Cloud Mirror Gen 2
My Cloud DL2100
My Cloud DL4100
My Cloud EX2100
WD Cloud
My Cloud
My Cloud Home
My Cloud OS 5
Gentoo Linux
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
Fedora
SUSE Linux Enterprise Workstation Extension 12
Slackware Linux
Ubuntu
Netatalk
QNAP QTS
netatalk (Ubuntu package)
libatalk12
netatalk-devel
netatalk-debugsource
netatalk
libatalk12-debuginfo
netatalk-debuginfo
net-fs/netatalk
QuTS hero

How to mitigate CVE-2022-22995

Install updates from vendor's website.

My Cloud OS 5 - addressed in versions 5.19.117, 7.16-220
Netatalk - update to 3.1.18
netatalk (Ubuntu package) - update to Ubuntu Pro
QuTS hero - update to h5.2.5.3138 build 20250519
libatalk12 - update to 3.1.0-3.22.1
netatalk-devel - update to 3.1.0-3.22.1
netatalk-debugsource - update to 3.1.0-3.22.1
netatalk - update to 3.1.0-3.22.1
libatalk12-debuginfo - update to 3.1.0-3.22.1
netatalk-debuginfo - update to 3.1.0-3.22.1
netatalk - update to 3.1.18
net-fs/netatalk - update to 3.1.18
netatalk - addressed in versions 3.1.18-1.el7, 3.1.18-1.el8, 3.1.18-1.el9, 3.1.18-1.fc37, 3.1.18-1.fc38, 3.1.18-1.fc39
QNAP QTS - update to 5.2.5.3145 20250526

External References

Related Security Bulletins