CVE-2019-18929: Buffer Overflow
Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest accounts) to remotely execute arbitrary code via a downloadmgr.cgi stack-based buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-18929?
CVE-2019-18929 is a vulnerability in the Western Digital My Cloud EX2 Ultra firmware 2.31.183 that allows web users, including guest accounts, to remotely execute arbitrary code via a stack-based buffer overflow in the download_mgr.cgi script.
What is the severity of CVE-2019-18929?
CVE-2019-18929 has a severity rating of 8.8 (critical).
How does CVE-2019-18929 affect me?
If you are using the Western Digital My Cloud EX2 Ultra firmware version 2.31.183, your system is vulnerable to remote code execution by web users, including guest accounts.
How can I fix CVE-2019-18929?
To fix CVE-2019-18929, you should update your Western Digital My Cloud EX2 Ultra firmware to version 2.31.195 or later.
Where can I find more information about CVE-2019-18929?
You can find more information about CVE-2019-18929 in the following references: [GitHub Description](https://github.com/DelspoN/CVE/blob/master/CVE-2019-18929/description.txt), [GitHub Repository](https://github.com/DelspoN/CVE/tree/master/CVE-2019-18929).