9.5 High
AI Score
Confidence
High
0.002 Low
EPSS
Percentile
57.0%
Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation.
github.com/pedrib/PoC/blob/master/advisories/Pwn2Own/Tokyo_2020/weekend_destroyer/weekend_destroyer.md
krebsonsecurity.com/2021/07/another-0-day-looms-for-many-western-digital-users/
www.youtube.com/watch?v=vsg9YgvGBec