CVE-2021-35941

Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory...

Basic Information

CVE State
PUBLISHED
Reserved Date
June 29, 2021
Published Date
June 29, 2021
Last Updated
August 04, 2024
Vendor
Western Digital
Product
WD My Book Live, WD My Book Live Duo
Description
Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than CVE-2018-18472.

CVSS Scores

CVSS v3.1

7.5 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v2.0

5.0

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Exploit Status

Exploited in the Wild
Yes (2021-06-29 20:22:43 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2021-06-29 20:22:43 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel