Vulnerability CVE-2021-36225


Published: 2023-02-06

Description:
Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation.

 References:
https://krebsonsecurity.com/2021/07/another-0-day-looms-for-many-western-digital-users/
https://github.com/pedrib/PoC/blob/master/advisories/Pwn2Own/Tokyo_2020/weekend_destroyer/weekend_destroyer.md
https://www.youtube.com/watch?v=vsg9YgvGBec

Copyright 2026, cxsecurity.com

 

Back to Top