← back
CVE-2018-18472observed exploitation

CVE-2018-18472

37Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendepss 30%
from disclosure to weapon
Published on NVDJun 19
VulnCheckJun 19
exploitation probability
30%top 2% of all CVEs
observed exploitation
yesVulnCheck
Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter. It can be triggered by anyone who knows the IP address of the affected device, as exploited in the wild in June 2021 for factory reset commands,
Affected products
n/a · n/a