Описание
Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114.
Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-27158
- https://www.comparitech.com/blog/information-security/security-vulnerabilities-80000-devices-update-now
- https://www.westerndigital.com/support/productsecurity
- https://www.westerndigital.com/support/productsecurity/wdc-20007-my-cloud-firmware-version-5-04-114
Связанные уязвимости
CVSS3: 9.8
nvd
больше 5 лет назад
Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114.
CVSS3: 9.8
fstec
больше 5 лет назад
Уязвимость компонента cgi_api.php микропрограммного обеспечения сетевого хранилища Western Digital MyCloud NAS, позволяющая нарушителю выполнить произвольный код