This vulnerability allows remote attackers to bypass authentication on affected installations of Western Digital MyCloud PR4100. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mod_rewrite module. The issue results from the way the software parses URLs to make authorization decisions. An attacker can leverage this vulnerability to bypass authentication on the system.
Affected Software | Affected Version | How to fix |
---|---|---|
Western Digital My Cloud PR4100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-CAN-12465 is classified as critical due to the potential for remote exploitation.
The affected product for ZDI-CAN-12465 is the Western Digital MyCloud PR4100.
To fix ZDI-CAN-12465, update the firmware of your Western Digital MyCloud PR4100 to the latest version that addresses this vulnerability.
Yes, ZDI-CAN-12465 can be exploited without authentication, allowing attackers to bypass security measures.
ZDI-CAN-12465 is an authentication bypass vulnerability that affects the mod_rewrite module.