CVE-2018-18472
9.8
CRITICAL · CVSS 3.0 · EPSS 30.3% (pctl 98)
Patch early
EPSS 30.3% — above the 10% action threshold.
Description
Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter. It can be triggered by anyone who knows the IP address of the affected device, as exploited in the wild in June 2021 for factory reset commands,
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 30.28% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-06-19 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| westerndigital | my book live |
| westerndigital | my book live firmware |
References
- https://community.wd.com/t/action-required-on-my-book-live-and-my-book-live-duo/268147
- https://www.westerndigital.com/support/productsecurity/wdc-21008-recommended-security-measures-wd-mybooklive-wd-mybookliveduo
- https://www.wizcase.com/blog/hack-2018/
- https://community.wd.com/t/action-required-on-my-book-live-and-my-book-live-duo/268147
- https://www.westerndigital.com/support/productsecurity/wdc-21008-recommended-security-measures-wd-mybooklive-wd-mybookliveduo
- https://www.wizcase.com/blog/hack-2018/
→ the Explorer · watch your stack · NVD