CVE-2015-7709
Western Digital Arkeia <11.0.12 - Command Injection
Title source: llmDescription
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execute arbitrary commands via a series of crafted requests involving the ARKFS_EXEC_CMD operation.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/37600
metasploit
WORKING POC
GREAT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/misc/arkeia_agent_exec.rb
Scores
EPSS
0.8839
EPSS Percentile
99.5%
Classification
CWE
CWE-264
Status
draft
Affected Products (1)
arkeia/western_digital_arkeia
< 11.0.12
Timeline
Published
Oct 05, 2015
Tracked Since
Feb 18, 2026