CVE-2019-16399
CRITICALWestern Digital WD My Book World - Auth Bypass
Title source: llmDescription
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker can easily enable SSH from /admin/system_advanced.php?lang=en and login with the default root password welc0me.
Exploits (1)
exploitdb
WORKING POC
by Noman Riffat · textwebappshardware
https://www.exploit-db.com/exploits/47399
Scores
CVSS v3
9.8
EPSS
0.1090
EPSS Percentile
93.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-798
Status
published
Products (1)
westerndigital/wd_my_book_firmware
< 1.02.12
Published
Sep 18, 2019
Tracked Since
Feb 18, 2026