References https://mrxn.net/jswz/west-nas-addons-upload-rce.html https://www.gm7.org/archives/48360 https://mrxn.net/jswz/Western-Digital-My-Cloud-NAS-multi_uploadify-rce.html https://www.tenablecloud.cn/plugins/nessus/105732 https://cn-sec.com/archives/4395990.html https://cloud.tencent.com/developer/article/1043712 https://nosec.org/m/share/2664.html https://www.anquanke.com/post/id/93963 https://pentest-tools.com/vulnerabilities-exploits/western-digital-my-cloud-file-upload-vulnerability_7211 https://mrxn.net/jswz/west-nas-php-upload-rce.html https://www.gzzknt.cn/views/safe/Security_Bulletin/CNTA-2018-0003.shtml https://cn-sec.com/archives/5061851.html https://sec-consult.com/vulnerability-lab/advisory/unauthenticated-os-command-injection-arbitrary-file-upload-in-western-digital-my-cloud/ https://www.exploit-db.com/exploits/43435 https://www.tenable.com/plugins/nessus/105732 https://nvd.nist.gov/vuln/detail/CVE-2017-17560
Related VulnerabilitiesPoCCVE-2026-5524: Divi Form Builder <=5.1.8 - Unauthenticated Arbitrary File Upload RCEPoCCVE-2026-32475: Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form HandlerFileRise /uploads 文件读取漏洞(CVE-2026-25231)鎧應科技|CMS-WS/CMS-SE/SMP - Arbitrary File Upload網韻資訊|NewSiteServer (NSS)新式校園網站系統 - Arbitrary File UploadPoCCVE-2026-0558: LolLMS <= 2.2.0 - Unauthenticated File UploadPoCCVE-2026-13001: Podlove Podcast Publisher <= 4.5.1 - Arbitrary File UploadPoCCVE-2026-57827: RSFiles! for Joomla - Arbitrary File UploadPoCibm-websphere-ssrf: IBM WebSphere HCL Digital Experience - Server-Side Request ForgeryPoCmonitorr-file-upload: Monitorr Services Configuration - Arbitrary File Upload二一零零科技|公文管理系統 - Arbitrary File UploadPoCCVE-2024-56064: WP SuperBackup <= 2.3.3 - Unauthenticated Arbitrary File Upload to RCEPoCCVE-2026-14483: Realtyna Organic IDX/WPL <= 5.2.0 - Unauthenticated Arbitrary File Upload