Friday, January 5, 2018

Are you using WD MyCloud device? - It might have a few free features (I mean vulnerabilities)


  1. A secret hard-coded backdoor that could allow remote attackers to gain unrestricted root access to the device. 
  2. Cross-site request forgery
  3. Command injection
  4. Denial of Service
  5. Information disclosure



Noteworthy, James Bercegay of GulfTech contacted the vendor and reported the issues in June last year. The vendor confirmed the vulnerabilities and requested a period of 90 days until full disclosure.

 On 3rd January (that's almost after 180 days), GulfTech publicly disclosed the details of the vulnerabilities, which are still unpatched

For More
https://thehackernews.com/2018/01/western-digital-mycloud.html

No comments:

Post a Comment