CVE-2018-9148
CRITICALWestern Digital My Cloud Firmware v04.05.00-320 - Authentication Bypass via Session Token in Filename
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-9148. PoCs published by Sven Fassbender.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in TwonkyMedia Server versions 7.0.11-8.5. It allows an attacker to set the 'contentbase' parameter to '/../' via the 'rpc/set_all' endpoint, enabling unauthorized filesystem browsing outside user-specified shares.
Description
Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass authentication by listing a directory. NOTE: this can be exploited in conjunction with CVE-2018-7171 for remote authentication bypass within a product that uses My Cloud.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in TwonkyMedia Server versions 7.0.11-8.5. It allows an attacker to set the 'contentbase' parameter to '/../' via the 'rpc/set_all' endpoint, enabling unauthorized filesystem browsing outside user-specified shares.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H