A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files. This could lead to a full NAS compromise and would give remote execution capabilities to the attacker.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/H4lo/awesome-IoT-security-article