peter bassill · operator
$ cve CVE-2018-18472 JSON

CVE-2018-18472

9.8
CRITICAL · CVSS 3.0 · EPSS 30.3% (pctl 98)

Patch early

EPSS 30.3% — above the 10% action threshold.

Description

Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter. It can be triggered by anyone who knows the IP address of the affected device, as exploited in the wild in June 2021 for factory reset commands,

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS30.28% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2019-06-19
Last modified2026-06-17

Affected (2)

VendorProduct
westerndigitalmy book live
westerndigitalmy book live firmware

References

→ the Explorer  ·  watch your stack  ·  NVD