CVE-2016-10107 describes an unauthenticated remote command injection vulnerability in Western Digital MyCloud NAS firmware version 2.11.142, specifically within the index.php page, exploitable through a modified Cookie header. This critical vulnerability, with a CVSS score of 9.8, allows an attacker to execute arbitrary commands as root with low attack complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, there is significant community discussion and media coverage, indicating awareness, though no public exploit intelligence (Metasploit, Nuclei, ExploitDB) is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.11.142CPE matchmatch criteria | cpe:2.3:a:western_digital:mycloud_nas:2.11.142:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.