CVE-2018-18472
Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 30.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter. It can be triggered by anyone who knows the IP address of the affected device, as exploited in the wild in June 2021 for factory reset commands,
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 30.28% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- westerndigital/my book live firmware
- Source
- cve@mitre.org
References
- https://community.wd.com/t/action-required-on-my-book-live-and-my-book-live-duo/268147
- https://www.westerndigital.com/support/productsecurity/wdc-21008-recommended-security-measures-wd-mybooklive-wd-mybookliveduo
- https://www.wizcase.com/blog/hack-2018/Third Party Advisory
- https://community.wd.com/t/action-required-on-my-book-live-and-my-book-live-duo/268147
- https://www.westerndigital.com/support/productsecurity/wdc-21008-recommended-security-measures-wd-mybooklive-wd-mybookliveduo
- https://www.wizcase.com/blog/hack-2018/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.