CVE-2021-36225 Information

Description

Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts as demonstrated by API commands for firmware uploads and installation.

Reference

https://krebsonsecurity.com/2021/07/another-0-day-looms-for-many-western-digital-users/ https://github.com/pedrib/PoC/blob/master/advisories/Pwn2Own/Tokyo_2020/weekend_destroyer/weekend_destroyer.md https://www.youtube.com/watch?v=vsg9YgvGBec

Share on: