ZeroHour
The Recordpublished ()ingested

Western Digital blames 2018 bug for mass

mediumVulnerabilityimportance 35CVE-2018-18472

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-18472
Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/la

Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter. It can be triggered by anyone who knows the IP address of the affected device, as exploited in the wild in June 2021 for factory reset commands,

NVD description · AI analysis pending
9.830%
  • westerndigital my book live firmware
Full article325 words · extracted from therecord.media · click to collapse

US-based Western Digital has blamed an old 2018 vulnerability for a series of attacks during which a mysterious entity has triggered mass-factory resets that have wiped user data from internet-exposed My Book Live and My Book Live Duo network-attached storage (NAS) devices.

According to a WD spokesperson, the attacker appears to have used a vulnerability tracked as CVE-2018-18472 to trigger the attacks earlier this week.

Discovered by security researchers Paulos Yibelo and Daniel Eshetu, the CVE-2018-18472 bug allows remote threat actors to bypass authentication on the WD My Book Live NAS devices and run commands with root privileges.

In normal cases, threat actors would abuse such a vulnerability to add the device to a DDoS or cryptomining botnet or encrypt and ransom a device's data.

But in messages posted on Reddit and WD's official forums this week, it appears that a threat actor has chained this vulnerability with a factory reset procedure that wipes data on the NAS and returns the device to standard settings.

It is unclear if the attack is on purpose or the result of a coding mistake on the threat actor's part.

The damage caused by the attacker is also unknown.

The good news is that the number of My Book Live and My Book Live Duo impacted by the mass-wipes is likely to be small compared to the company's other NAS models.

WD says the two My Book Live versions seen impacted by the attack have been off the market for almost a decade.

However, this is also bad news, as the devices have also not received any patches for the 2018 bug. WD said the last firmware update for My Book Live NAS devices was released in 2015.

In a support page, the company said it's working on solutions to address the attacks. In the meantime, a WD spokesperson advised that My Book Live device owners disconnect their devices from the internet until a solution is on hand.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/western-digital-blames-2018-bug-for-mass-wiping-attacks-on-old-nas-devices