SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-18472

Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter.

CRITICAL 9.8EPSS 30.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 30.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter. It can be triggered by anyone who knows the IP address of the affected device, as exploited in the wild in June 2021 for factory reset commands,

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
30.28% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-78
Affected
westerndigital/my book live firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.