Back to Database
Status published
Medium
CVE-2022-29837
Path traversal Vulnerability in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi Devices
Vulnerability Description
A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to a code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-29837
Credits & Attribution
No credits recorded in the NVD database.
More from Western Digital
View All →CVE-2025-30248
DLL hijacking in the WD Discovery Installer in Western Digital...
High
8.9
CVE-2025-30247
An OS command injection vulnerability in user interface in Western...
Critical
9.3
CVE-2024-22170
Unchecked buffer in Dynamic DNS client
Critical
9.2
CVE-2024-22169
Misconfiguration in node.js causing a code execution in WD Discovery
High
7.1
CVE-2024-22168
Cross-Site Scripting (XSS) vulnerability on Western Digital My Cloud and SanDisk ibi Web Apps
Medium
5.9
Affected Vendor
Western Digital
View all reports →Affected Software
My Cloud Home, ibi
Vulnerable Versions:
My Cloud Home , My Cloud Home Duo, ibi
Timeline
Official Publish:
December 1st, 2022
Last Modified:
April 24th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N