PT-2025-39899 · Western Digital · My Cloud

·

CVE-2025-30247

·

Published

2025-09-26

·

Updated

2026-06-13

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Western Digital My Cloud versions prior to 5.31.108
Description An OS command injection flaw exists in the user interface of the firmware. This issue allows remote attackers to execute arbitrary system commands by sending a specially crafted HTTP POST request. Approximately 166,900 devices are potentially affected worldwide.
Recommendations Update to version 5.31.108.

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12426
CVE-2025-30247

Affected Products

My Cloud