CVE-2020-27159
9.8
CRITICAL · CVSS 3.1 · EPSS 6.2% (pctl 93)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western Digital My Cloud NAS devices prior to 5.04.114
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.21% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-10-27 |
| Last modified | 2026-06-17 |
Affected (6)
| Vendor | Product |
|---|---|
| westerndigital | my cloud ex4100 |
| westerndigital | my cloud expert series ex2 |
| westerndigital | my cloud firmware |
| westerndigital | my cloud mirror - gen 2 |
| westerndigital | my cloud pr2100 |
| westerndigital | my cloud pr4100 |
References
- https://www.comparitech.com/blog/information-security/security-vulnerabilities-80000-devices-update-now/
- https://www.westerndigital.com/support/productsecurity
- https://www.westerndigital.com/support/productsecurity/wdc-20007-my-cloud-firmware-version-5-04-114
- https://www.comparitech.com/blog/information-security/security-vulnerabilities-80000-devices-update-now/
- https://www.westerndigital.com/support/productsecurity
- https://www.westerndigital.com/support/productsecurity/wdc-20007-my-cloud-firmware-version-5-04-114
→ the Explorer · watch your stack · NVD