Loading
Generated remediation guidance and an executive summary. No account required.
Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest account) to remotely execute arbitrary code via a stack-based buffer overflow. There is no size verification logic in one of functions in libscheddl.so, and download_mgr.cgi makes it possible to enter large-sized f_idx inputs.
Use CWE-787, Western Digital vendor hub and My Cloud Ex2 Ultra Firmware product page to widen CVE-2019-18930 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-9951, CVE-2018-17153 and CVE-2019-18931 for nearby disclosures in the same product family.