CVE-2019-18930

HIGH

Western Digital My Cloud EX2 Ultra 2.31.183 - RCE

Title source: llm
STIX 2.1

Description

Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest account) to remotely execute arbitrary code via a stack-based buffer overflow. There is no size verification logic in one of functions in libscheddl.so, and download_mgr.cgi makes it possible to enter large-sized f_idx inputs.

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0074
EPSS Percentile 73.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (1)
western_digital/my_cloud_ex2_ultra_firmware 2.31.183
Published Nov 13, 2019
Tracked Since Feb 18, 2026