Westerndigital
westerndigital
82 CVEs • 194 products
Products (194)
Click to collapseToggle
Products (194)
Click to collapse
CVEs (82)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Westerndigital 1My Cloud Os Jun 17, 2026 Jan 28, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed...Show more |
A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecured HTTP call. Addressed this vulnerability by disabling checks for inter...Show more |
A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices. Addressed this vulnerability by changing access...Show more |
1Westerndigital 1My Cloud Os Jun 17, 2026 Jan 13, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploited by unauthenticated attackers on the network. Addressed the vulnerability by adding defenses agai...Show more |
1Westerndigital 1Edgerover Jun 17, 2026 Jan 13, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It would be more difficult for an authenticated attacker to now traverse through the files and directo...Show more |
1Westerndigital 2Wd My Book Live Duo Firmware Wd My Book Live FirmwareJun 17, 2026 Jun 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a...Show more |
Western Digital EdgeRover before 0.25 has an escalation of privileges vulnerability where a low privileged user could load malicious content into directories with higher privileges, because of how Node.js is used. An att...Show more |
The iOS and macOS apps before 1.4.1 for the Western Digital G-Technology ArmorLock NVMe SSD store keys insecurely. They choose a non-preferred storage mechanism if the device has Secure Enclave support but lacks biometri...Show more |
Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files). |
Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account. |
1Westerndigital 1My Cloud Os 5 Jun 17, 2026 Dec 12, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to gain access to the device. |
1Westerndigital 1My Cloud Os 5 Jun 17, 2026 Dec 1, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a coo...Show more |
1Westerndigital 1My Cloud Os 5 Jun 17, 2026 Dec 1, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a coo...Show more |
1Westerndigital 1My Cloud Os 5 Jun 17, 2026 Dec 1, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unauthenticated user to execute privileged commands on the device. |
3Linaro TrustedfirmwareWesterndigital5Inand Cl Em132 Firmware Inand Ix Em132 FirmwareInand Ix Em132 Xi Firmware+2 moreJun 17, 2026 Nov 18, 2020 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 Western Digital has identified a security vulnerability in the Replay Protected Memory Block (RPMB) protocol as specified in multiple standards for storage device interfaces, including all versions of eMMC, UFS, and NVMe...Show more |
1Westerndigital 1My Cloud Firmware Jun 17, 2026 Oct 29, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with resultant escalation of privileges. |
1Westerndigital 1My Cloud Firmware Jun 17, 2026 Oct 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114 (issue 3 of 3). |
1Westerndigital 1My Cloud Firmware Jun 17, 2026 Oct 27, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western Digital My Cloud NAS devices prior to 5.04.114 |
1Westerndigital 1My Cloud Firmware Jun 17, 2026 Oct 27, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114. |
1Westerndigital 1My Cloud Firmware Jun 17, 2026 Oct 27, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western Digital My Cloud Devices prior to 5.4.1140. |