packetstormsecurity.com
http://packetstormsecurity.com/files/154524/Western-Digital-My-Book-World-II-NAS-1.02.12-Hardcoded-Credential.html CVE-2019-16399
CRITICAL
Western Digital My Book World II NAS 1.02.12 - Authentication Bypass / Command Execution
Record summary
CVE-2019-16399 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker can easily enable SSH from /admin/system_advanced.php?lang=en and login with the default root password welc0me.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWestern Digital My Book World II NAS 1.02.12 - Authentication Bypass / Command ExecutionExploitDB exploitby Noman RiffatNot analyzed1 file
References
3gist.github.com
https://gist.github.com/pak0s/22ad6bae26198ebcd137b61adb6fcfe6 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-16399