CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines, daily updates. Fast, privacy‑respecting. No ads, no tracking.

Critical Command Injection Vulnerability in Western Digital My Cloud NAS Devices

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Western Digital has released firmware updates to address a critical-severity OS command injection vulnerability (CVE-2025-30247) affecting multiple My Cloud NAS models. The flaw allows remote attackers to execute arbitrary system commands through specially crafted HTTP POST requests. The vulnerability impacts several models, including My Cloud PR2100, PR4100, EX4100, EX2 Ultra, Mirror Gen 2, DL2100, EX2100, DL4100, and WDBCTLxxxxxx-10. Users are advised to update to firmware version 5.31.108 to mitigate the risk. Two models, My Cloud DL4100 and DL2100, have reached end of support and may not receive updates.

Timeline

  1. 30.09.2025 18:07 1 articles · 9h ago

    Critical Command Injection Vulnerability in Western Digital My Cloud NAS Devices

    Western Digital has released firmware updates to address a critical-severity OS command injection vulnerability (CVE-2025-30247) affecting multiple My Cloud NAS models. The flaw allows remote attackers to execute arbitrary system commands through specially crafted HTTP POST requests. The vulnerability impacts several models, including My Cloud PR2100, PR4100, EX4100, EX2 Ultra, Mirror Gen 2, DL2100, EX2100, DL4100, and WDBCTLxxxxxx-10. Users are advised to update to firmware version 5.31.108 to mitigate the risk. Two models, My Cloud DL4100 and DL2100, have reached end of support and may not receive updates.

    Show sources

Information Snippets