CVE-2021-36226: Critical severity western digital my cloud os 5 vulnerability
Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-36226?
CVE-2021-36226 refers to a vulnerability found in Western Digital My Cloud devices before OS5 that allows for the installation of unauthorized firmware upgrade files.
How severe is CVE-2021-36226?
CVE-2021-36226 has a severity score of 9.8, indicating a critical vulnerability.
Which software versions are affected by CVE-2021-36226?
CVE-2021-36226 affects Western Digital My Cloud devices before OS5 with a version up to 5.02.104.
How can I fix CVE-2021-36226?
To fix CVE-2021-36226, users should update their Western Digital My Cloud devices to OS5 or above.
Where can I find more information about CVE-2021-36226?
More information about CVE-2021-36226 can be found in the following references: [Link 1](https://github.com/pedrib/PoC/blob/master/advisories/Pwn2Own/Tokyo_2020/weekend_destroyer/weekend_destroyer.md), [Link 2](https://krebsonsecurity.com/2021/07/another-0-day-looms-for-many-western-digital-users/), [Link 3](https://www.youtube.com/watch?v=vsg9YgvGBec).