ZDI-23-849: (Pwn2Own) Western Digital MyCloud PR4100 do_reboot Command Injection Remote Code Execution Vulnerability
Published Jun 8, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Western Digital MyCloud PR4100 NAS devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
1 affected component
Western Digital MyCloud PR4100
Event History
Jun 8, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-849?
The severity of ZDI-23-849 is critical due to the potential for remote code execution.
2
How do I fix ZDI-23-849?
To fix ZDI-23-849, apply the latest security updates provided by Western Digital for your MyCloud PR4100 device.
3
Which devices are affected by ZDI-23-849?
ZDI-23-849 affects Western Digital MyCloud PR4100 NAS devices.
4
Can ZDI-23-849 be exploited without authentication?
No, exploitation of ZDI-23-849 requires authentication, but the existing authentication can be bypassed.
5
What type of attack is enabled by ZDI-23-849?
ZDI-23-849 enables remote attackers to execute arbitrary code on the affected devices.