CVE-2019-16399

CRITICAL

Western Digital WD My Book World - Auth Bypass

Title source: llm

Description

Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker can easily enable SSH from /admin/system_advanced.php?lang=en and login with the default root password welc0me.

Exploits (1)

exploitdb WORKING POC
by Noman Riffat · textwebappshardware
https://www.exploit-db.com/exploits/47399

Scores

CVSS v3 9.8
EPSS 0.1090
EPSS Percentile 93.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (1)
westerndigital/wd_my_book_firmware < 1.02.12
Published Sep 18, 2019
Tracked Since Feb 18, 2026