CVE-2021-36226
9.8CRITICALWestern Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.
Published: 2/6/2023Updated: 3/26/2025
Description
Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.
AI AnalysisPowered by AI
Affected Products
westerndigitalmy_cloud_os
westerndigitalmy_cloud_pr4100
-
References
- https://github.com/pedrib/PoC/blob/master/advisories/Pwn2Own/Tokyo_2020/weekend_destroyer/weekend_destroyer.mdExploitPatchThird Party Advisory
- https://krebsonsecurity.com/2021/07/another-0-day-looms-for-many-western-digital-users/ExploitPatchThird Party Advisory
- https://www.youtube.com/watch?v=vsg9YgvGBecExploitPatchThird Party Advisory
- https://github.com/pedrib/PoC/blob/master/advisories/Pwn2Own/Tokyo_2020/weekend_destroyer/weekend_destroyer.mdExploitPatchThird Party Advisory
- https://krebsonsecurity.com/2021/07/another-0-day-looms-for-many-western-digital-users/ExploitPatchThird Party Advisory
- https://www.youtube.com/watch?v=vsg9YgvGBecExploitPatchThird Party Advisory