CVE-2018-18472 is a critical remote command execution vulnerability affecting all versions of Western Digital My Book Live and My Book Live Duo devices. The flaw allows an unauthenticated attacker to execute arbitrary commands as root by injecting shell metacharacters into the language parameter of the /api/1.0/rest/language_configuration API endpoint. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability was actively exploited in the wild in June 2021 to factory reset devices, prompting significant community discussion and media coverage, with Western Digital advising users to disconnect affected devices from the internet. While no public exploit code is listed in Metasploit, Nuclei, or ExploitDB, its real-world exploitation confirms its high risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:westerndigital:my_book_live_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.