CVE-2016-10108: Command Injection
Published Jan 3, 2017
·Updated
Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/googleanalytics.php URL via a modified arg parameter in the POST data.
Affected Software
1 affected component
Western Digital MyCloud NAS=2.11.142
Event History
Jan 3, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10108?
CVE-2016-10108 is considered critical due to its potential for unauthenticated remote command injection as root.
2
How do I fix CVE-2016-10108?
To fix CVE-2016-10108, update the Western Digital MyCloud NAS firmware to the latest version available from the manufacturer's website.
3
What does CVE-2016-10108 affect?
CVE-2016-10108 affects Western Digital MyCloud NAS version 2.11.142.
4
What type of attack is CVE-2016-10108 associated with?
CVE-2016-10108 is associated with unauthenticated remote command injection attacks.
5
Can CVE-2016-10108 be exploited without authentication?
Yes, CVE-2016-10108 can be exploited without any authentication, allowing attackers to execute commands as root.