Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Low
CVE-2021-35941
Disclosure Date: June 29, 2021 (last updated February 22, 2025)
Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than CVE-2018-18472.
1
Attacker Value
Unknown
CVE-2019-16399
Disclosure Date: September 18, 2019 (last updated November 27, 2024)
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker can easily enable SSH from /admin/system_advanced.php?lang=en and login with the default root password welc0me.
0