A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to execute code in the context of the root user.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-34161 | A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to execute code in the context of the root user. |
Fixes
Solution
Western Digital recommends that users promptly update their devices to the latest firmware by clicking on the firmware update notification.
Workaround
No workaround given by the vendor.
References
History
Fri, 04 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WDC PSIRT
Published:
Updated: 2025-04-04T20:33:03.268Z
Reserved: 2022-04-27T00:00:00.000Z
Link: CVE-2022-29843
Updated: 2024-08-03T06:33:42.818Z
Status : Modified
Published: 2023-01-26T21:15:33.577
Modified: 2024-11-21T06:59:47.987
Link: CVE-2022-29843
No data.
OpenCVE Enrichment
No data.
EUVD