S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 7, 2024

CVE-2016-10108 Scanner

Detects 'OS Command Injection' vulnerability in Western Digital MyCloud NAS affects v. 2.11.142.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2016-10108
9.8
CVSS

Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg parameter in the POST data.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Western Digital MyCloud NAS is a network-attached storage device used for storing and sharing data across a local area network. It is a popular device among both individuals and businesses due to its ease of use and convenience. The MyCloud NAS allows users to access their files from anywhere, making it an attractive option for remote work and collaboration.

CVE-2016-10108 is a vulnerability detected in the Western Digital MyCloud NAS 2.11.142. This vulnerability allows unauthenticated remote command injection as root through a modified arg parameter in the POST data. This vulnerability can be exploited by attackers to gain unauthorized access to the device and steal sensitive data or install malicious software.

When exploited, CVE-2016-10108 can lead to serious consequences for users of the MyCloud NAS. Attackers can gain complete control over the device, allowing them to view and steal sensitive personal or business data stored on the device. They can also install malware or ransomware, encrypting or deleting important files and causing significant damage or loss.

At s4e.io, we offer a range of pro features that can help individuals and businesses stay informed about vulnerabilities in their digital assets. With our platform, users can quickly and easily learn about the latest security threats, assess their risk exposure, and take action to protect themselves against potential attacks. By using s4e.io, users can safeguard their digital assets and ensure the safety and security of their personal and business data.

 

REFERENCES

Solution Advice

To protect against CVE-2016-10108, users of the MyCloud NAS can take the following precautions:

  • Update to the latest firmware version that includes a patch for the vulnerability
  • Disable remote access to the device if it is not needed for regular use
  • Use strong, unique passwords for all users on the device
  • Monitor network traffic for any suspicious activity
  • Keep backups of important data in case of a ransomware attack or other data loss event

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2016-10108 scanner - OS Command Injection vulnerability in Western Digital MyCloud NAS | S4E