ZDI-23-1051: Western Digital MyCloud PR4100 CGI API Command Injection Remote Code Execution Vulnerability
Published Aug 9, 2023
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of the Western Digital MyCloud PR4100 NAS device. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
Western Digital MyCloud PR4100
Event History
Aug 9, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1051?
ZDI-23-1051 is classified as a high-severity vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix ZDI-23-1051?
To fix ZDI-23-1051, update your Western Digital MyCloud PR4100 NAS device to the latest firmware version provided by Western Digital.
3
Who is affected by ZDI-23-1051?
Users of the Western Digital MyCloud PR4100 NAS device are affected by ZDI-23-1051.
4
Can ZDI-23-1051 be exploited remotely?
No, ZDI-23-1051 requires authentication, meaning it cannot be exploited remotely without valid credentials.
5
What type of attack does ZDI-23-1051 facilitate?
ZDI-23-1051 facilitates an arbitrary code execution attack on the affected devices.