Showing 1 vulnerability on this page for wd_my_book_live_firmware

Signals CISA KEV Ransomware Nuclei
Western Digital vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Western Digital wd_my_book_live_firmware Missing Authentication for Critical Function

Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than CVE-2018-18472.

CWE-287CWE-306Jun 29, 2021
CVSS7.5v3.1EPSS12.7%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX