A remote code execution vulnerability was discovered on...
Critical severity
Unreviewed
Published
Jan 29, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Jan 28, 2022
Published to the GitHub Advisory Database
Jan 29, 2022
Last updated
Feb 3, 2023
A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading through an unsecured HTTP call. This was a result insufficient verification of calls to the device. The vulnerability was addressed by disabling checks for internet connectivity using HTTP.
References