← Back to browse · API

CVE-2022-29842

Severity
CRITICAL
CVSS
9.8
EPSS
0.01836
Risk score
39.84
CISA KEV
No
PoC
No
Published
2023-05-10
Modified
2025-01-24
First seen
2026-08-07
Aliases
EUVD-2022-34160, GHSA-JGF2-QHGR-GP37
Products
Western Digital:My Cloud OS 5 0 <5.26.119
Sources
euvd EUVD-2022-34160

Description

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 devicesThis issue affects My Cloud OS 5: before 5.26.119.

References