CVE-2018-18472: OS Command Injection
Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/languageconfiguration language parameter. It can be triggered by anyone who knows the IP address of the affected device, as exploited in the wild in June 2021 for factory reset commands,
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18472?
CVE-2018-18472 is considered a critical vulnerability due to its potential for remote command execution.
How do I fix CVE-2018-18472?
To fix CVE-2018-18472, it is advised to disable remote access on the affected WD My Book Live devices.
Who is affected by CVE-2018-18472?
All versions of WD My Book Live and WD My Book Live Duo are affected by CVE-2018-18472.
What kind of vulnerability is CVE-2018-18472?
CVE-2018-18472 is classified as a root Remote Command Execution vulnerability.
Can CVE-2018-18472 be exploited remotely?
Yes, CVE-2018-18472 can be exploited remotely by anyone who knows the IP address of the affected device.