CVE-2021–3310 Western Digital MyCloud PR4100 Link Resolution Information Disclosure Vulnerability

Default Share permissions
SMB.conf settings
AFP Configuration
Symlinks enabled
Access to the overly permissive shadow file readable by “nobody”
insecure shadow file permissions
proper shadow file permissions
php default configuration / save path
“secured” session file
Sending our request with the leaked cookie
csrf_token_check with one fatal flaw
exploit attempt with leaked session token and CSRF bypass
The fruits of our labor, a root shell!



