CVE-2019-16399: Westerndigital Wd My Book Firmware
Critical severity, CVSS 9.8. EPSS: 7.1% chance of exploitation in the next 30 days.
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker can easily enable SSH from /admin/system_advanced.php?lang=en and login with the default root password welc0me.
Affected products
- Westerndigital Wd My Book Firmware: up to and including 1.02.12
Published 2019-09-18. Last modified 2026-06-17.