Vulnerability Description
Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Westerndigital | My Cloud Os | < 5.02.104 |
| Westerndigital | My Cloud Pr4100 | - |
Related Weaknesses (CWE)
References
- https://github.com/pedrib/PoC/blob/master/advisories/Pwn2Own/Tokyo_2020/weekend_ExploitPatchThird Party Advisory
- https://krebsonsecurity.com/2021/07/another-0-day-looms-for-many-western-digitalExploitPatchThird Party Advisory
- https://www.youtube.com/watch?v=vsg9YgvGBecExploitPatchThird Party Advisory
- https://github.com/pedrib/PoC/blob/master/advisories/Pwn2Own/Tokyo_2020/weekend_ExploitPatchThird Party Advisory
- https://krebsonsecurity.com/2021/07/another-0-day-looms-for-many-western-digitalExploitPatchThird Party Advisory
- https://www.youtube.com/watch?v=vsg9YgvGBecExploitPatchThird Party Advisory
FAQ
What is CVE-2021-36225?
CVE-2021-36225 is a vulnerability with a CVSS score of 8.8 (HIGH). Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation.
How severe is CVE-2021-36225?
CVE-2021-36225 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-36225?
Check the references section above for vendor advisories and patch information. Affected products include: Westerndigital My Cloud Os, Westerndigital My Cloud Pr4100.