VendorsWestern Digitalmy_cloud_expert_series_ex2all versions
Vulnerabilities

Western Digital My Cloud Expert Series EX2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2020-27158
Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114.
Published 2020-10-27 · Modified
10.0EPSS 0.075
CVE-2020-27159
Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western Digital My Cloud NAS devices prior to 5.04.114
Published 2020-10-27 · Modified
10.0EPSS 0.062
CVE-2020-25765
Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western Digital My Cloud Devices prior to 5.4.1140.
Published 2020-10-27 · Modified
10.0EPSS 0.061
CVE-2020-27160
Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114 (issue 3 of 3).
Published 2020-10-27 · Modified
9.8EPSS 0.049
CVE-2020-12830
Addressed multiple stack buffer overflow vulnerabilities that could allow an attacker to carry out escalation of privileges through unauthorized remote code execution in Western Digital My Cloud devices before 5.04.114.
Published 2020-10-27 · Modified
9.8EPSS 0.033