ZDI-23-848: (Pwn2Own) Western Digital MyCloud PR4100 restsdk Directory Traversal Arbitrary File Read and Write Vulnerability
This vulnerability allows remote attackers to create and read arbitrary files on affected installations of Western Digital MyCloud PR4100 NAS devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-848?
The severity of ZDI-23-848 is critical due to remote exploitation potential and the ability to bypass authentication.
How do I fix ZDI-23-848?
To fix ZDI-23-848, update your Western Digital MyCloud PR4100 NAS to the latest firmware provided by Western Digital.
What type of attacks can be executed using ZDI-23-848?
ZDI-23-848 allows attackers to create and read arbitrary files on affected devices.
Is authentication required to exploit ZDI-23-848?
Yes, authentication is required, but the vulnerability allows for the existing authentication mechanism to be bypassed.
Which devices are affected by ZDI-23-848?
ZDI-23-848 affects the Western Digital MyCloud PR4100 NAS devices.