CVE-2020-27158: OS Command Injection
Published Oct 27, 2020
·Updated
Addressed remote code execution vulnerability in cgiapi.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114.
Affected Software
6 affected components
WesternDigital My Cloud Firmware<5.04.114
WesternDigital My Cloud Ex4100
WesternDigital My Cloud Expert Series Ex2
WesternDigital My Cloud Mirror - Gen 2
WesternDigital My Cloud Pr2100
WesternDigital My Cloud Pr4100
Event History
Oct 27, 2020
CVE Published
via MITRE·07:46 PM
Data Sourced
via MITRE·07:46 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-27158.
2
What is the severity of CVE-2020-27158?
The severity of CVE-2020-27158 is critical with a score of 9.8.
3
Which devices are affected by this vulnerability?
This vulnerability affects Western Digital My Cloud NAS devices prior to version 5.04.114.
4
How can I fix CVE-2020-27158?
To fix CVE-2020-27158, make sure to update your Western Digital My Cloud NAS device to version 5.04.114 or later.
5
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Western Digital support website.