CVE List

CVE-2022-29843

Severe 9.8

A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to execute code in the context of the root user.

Published January 26, 2023.

Affected software

Get alerts for Westerndigital My Cloud Pr2100 Firmware

Reference links