CVE-2023-22816: Westerndigital My Cloud OS
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to build files with redirects and execute larger payloads. This issue affects My Cloud OS 5 devices: before 5.26.300.
Affected products
- Westerndigital My Cloud OS: before 5.26.300 (fixed in 5.26.300)
Published 2023-06-30. Last modified 2026-06-17.