The company also provided new technical details about the zeroday, which is now being tracked as CVE-2021-35941. Company officials wrote:
We have heard concerns about the nature of this vulnerability and are sharing technical details to address these questions. We have determined that the unauthenticated factory reset vulnerability was introduced to the My Book Live in April of 2011 as part of a refactor of authentication logic in the device firmware. The refactor centralized the authentication logic into a single file, which is present on the device as
includes/component_config.php
and contains the authentication type required by each endpoint. In this refactor, the authentication logic insystem_factory_restore.php
was correctly disabled, but the appropriate authentication type ofADMIN_AUTH_LAN_ALL
was not added tocomponent_config.php
, resulting in the vulnerability. The same refactor removed authentication logic from other files and correctly added the appropriate authentication type to thecomponent_config.php
file.
The post added:
Read 26 remaining paragraphs | Comments