Unauthenticated File Upload Vulnerability in Western Digital My Cloud Devices
CVE-2019-9951
9.8CRITICAL
What is CVE-2019-9951?
Certain Western Digital My Cloud devices are susceptible to a critical security flaw that allows an unauthenticated user to upload arbitrary files through an unsecured endpoint. This vulnerability exists in the web interface, specifically in the 'uploadify.php' script of the firmware versions prior to 2.31.174. Due to the lack of authentication on this endpoint, attackers can exploit this vulnerability to upload malicious files, which may lead to unauthorized access and further compromise the integrity of the system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
