CVE-2020-27159

CRITICAL

Western Digital My Cloud <5.04.114 - RCE

Title source: llm
STIX 2.1

Description

Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western Digital My Cloud NAS devices prior to 5.04.114

Scores

CVSS v3 9.8
EPSS 0.0595
EPSS Percentile 92.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
westerndigital/my_cloud_firmware < 5.04.114
Published Oct 27, 2020
Tracked Since Feb 18, 2026