First published: Mon Feb 06 2023(Updated: )
Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Westerndigital My Cloud Os | <5.02.104 | |
Westerndigital My Cloud Pr4100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36226 refers to a vulnerability found in Western Digital My Cloud devices before OS5 that allows for the installation of unauthorized firmware upgrade files.
CVE-2021-36226 has a severity score of 9.8, indicating a critical vulnerability.
CVE-2021-36226 affects Western Digital My Cloud devices before OS5 with a version up to 5.02.104.
To fix CVE-2021-36226, users should update their Western Digital My Cloud devices to OS5 or above.
More information about CVE-2021-36226 can be found in the following references: [Link 1](https://github.com/pedrib/PoC/blob/master/advisories/Pwn2Own/Tokyo_2020/weekend_destroyer/weekend_destroyer.md), [Link 2](https://krebsonsecurity.com/2021/07/another-0-day-looms-for-many-western-digital-users/), [Link 3](https://www.youtube.com/watch?v=vsg9YgvGBec).