Blog | G5 Cyber Security

CVE-2018-18472: Western Digital My Book Live Mass Exploitation

Western Digital My Book Live device owners were finding their storage partitions were being wiped clean, meaning years of data some users have collected over time (home videos and pictures, etc.) were inexplicably gone. Western Digital has released a statement urging users to disconnect their device from the internet. The vulnerability allows simple unauthenticated remote command execution via a simple PUT request to the /api/1.0/rest/language_configuration endpoint. The WHOIS information of the remote IP address hosting the malicious payload (185.153.196.30) indicates the host resides in the Republic of Moldova. A reverse-DNS (PTR) record lookup indicates that the host is part of ClouDedic a presumed cloud service provider:”]

Source: https://censys.io/blog/cve-2018-18472-western-digital-my-book-live-mass-exploitation/

Exit mobile version