Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-10200 | Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter. It can be triggered by anyone who knows the IP address of the affected device, as exploited in the wild in June 2021 for factory reset commands, |
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:08:21.828Z
Reserved: 2018-10-18T00:00:00.000Z
Link: CVE-2018-18472
No data.
Status : Modified
Published: 2019-06-19T16:15:10.703
Modified: 2026-06-17T01:47:21.423
Link: CVE-2018-18472
No data.
OpenCVE Enrichment
No data.
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
EUVD