PT-2025-39899 · Western Digital · My Cloud

W1Th0Ut

·

Published

2025-09-26

·

Updated

2025-11-02

·

CVE-2025-30247

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Western Digital My Cloud NAS versions prior to 5.31.108
Description An OS command injection flaw exists in the user interface of Western Digital My Cloud NAS devices. This allows remote, unauthenticated attackers to execute arbitrary system commands by sending a specially crafted HTTP POST request. The flaw is present in versions of the firmware prior to 5.31.108. The vulnerability could lead to a full system compromise. Approximately 166,900 devices are potentially exposed. The vulnerability is exploited through crafted HTTP POST requests sent to vulnerable endpoints.
Recommendations Update the firmware to version 5.31.108 or newer.

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-12426
CVE-2025-30247

Affected Products

My Cloud