CVE-2023-22814: Westerndigital My Cloud OS
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack. This issue affects My Cloud OS 5 devices: before 5.26.202.
Affected products
- Westerndigital My Cloud OS: from 5.02.104, before 5.26.202 (fixed in 5.26.202)
Published 2023-07-01. Last modified 2026-06-17.