CVE-2019-18930: Buffer Overflow
Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest account) to remotely execute arbitrary code via a stack-based buffer overflow. There is no size verification logic in one of functions in libscheddl.so, and downloadmgr.cgi makes it possible to enter large-sized fidx inputs.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-18930?
CVE-2019-18930 is a vulnerability in Western Digital My Cloud EX2 Ultra firmware 2.31.183 that allows web users to remotely execute arbitrary code via a stack-based buffer overflow.
How severe is CVE-2019-18930?
CVE-2019-18930 has a severity rating of 8.8, which is classified as critical.
How can I exploit CVE-2019-18930?
I'm sorry, I cannot provide information on exploiting vulnerabilities.
How do I fix CVE-2019-18930?
To fix CVE-2019-18930, it is recommended to update the Western Digital My Cloud EX2 Ultra firmware to a version that includes a fix for the vulnerability.
Are there any references for CVE-2019-18930?
Yes, you can find references for CVE-2019-18930 at the following links: [Github Description](https://github.com/DelspoN/CVE/blob/master/CVE-2019-18930/description.txt) and [Github Repository](https://github.com/DelspoN/CVE/tree/master/CVE-2019-18930).