Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data. This command could be triggered by an attacker remotely to cause code execution and gain a reverse shell in Western Digital My Cloud OS 5 devices.This issue affects My Cloud OS 5: before 5.26.119.
No analysis available yet.
Remediation
Vendor Solution
Western Digital recommends that users promptly update their devices to the latest firmware by clicking on the firmware update notification.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-34159 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data. This command could be triggered by an attacker remotely to cause code execution and gain a reverse shell in Western Digital My Cloud OS 5 devices.This issue affects My Cloud OS 5: before 5.26.119. |
References
History
No history.
Subscriptions
Status: PUBLISHED
Assigner: WDC PSIRT
Published:
Updated: 2025-01-24T21:01:04.089Z
Reserved: 2022-04-27T20:53:48.676Z
Link: CVE-2022-29841
No data.
Status : Modified
Published: 2023-05-10T22:15:09.153
Modified: 2024-11-21T06:59:47.723
Link: CVE-2022-29841
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD