CVE-2023-22816: Limited Post-Authentication Remote Command Injection in My Cloud Products
A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to build files with redirects and execute larger payloads. This issue affects My Cloud OS 5 devices: before 5.26.300.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-22816?
CVE-2023-22816 is a post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to build files with redirects and execute larger payloads.
Which devices are affected by CVE-2023-22816?
This vulnerability affects Western Digital My Cloud OS 5 devices before version 5.26.300.
What is the severity level of CVE-2023-22816?
CVE-2023-22816 has a severity level of 8.8 (high).
How can I fix CVE-2023-22816?
To fix CVE-2023-22816, you should update your Western Digital My Cloud OS 5 device to version 5.26.300 or later.
Where can I find more information about CVE-2023-22816?
You can find more information about CVE-2023-22816 on the Western Digital support website at https://www.westerndigital.com/support/product-security/wdc-23010-my-cloud-firmware-version-5-26-300.