CVE-2019-16399: Critical severity western digital wd my book firmware vulnerability
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker can easily enable SSH from /admin/systemadvanced.php?lang=en and login with the default root password welc0me.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-16399?
CVE-2019-16399 has a high severity rating due to its potential for unauthorized access and exploitation.
How do I fix CVE-2019-16399?
To fix CVE-2019-16399, disable remote access features and change default passwords for the WD My Book World device.
What are the consequences of CVE-2019-16399?
The consequences of CVE-2019-16399 include unauthorized access to system settings and data, which could lead to further exploitation.
Which versions are affected by CVE-2019-16399?
CVE-2019-16399 affects all versions of the WD My Book World firmware up to and including version 1.02.12.
Is there a patch for CVE-2019-16399?
There is no official patch for CVE-2019-16399; users are advised to secure their devices using the recommended mitigation steps.