CVE-2021-3310: Western Digital MyCloud PR4100 Link Resolution Information Disclosure Vulnerability
Published Mar 10, 2021
·Updated
Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files).
Affected Software
18 affected components
WesternDigital My Cloud Os<5.10.122
WesternDigital My Cloud Dl2100
WesternDigital My Cloud Dl4100
WesternDigital My Cloud Ex2 Ultra
WesternDigital My Cloud Ex2100
WesternDigital My Cloud Ex4100
WesternDigital My Cloud Mirror Gen 2
WesternDigital My Cloud Pr2100
WesternDigital My Cloud Pr4100
All of the following
WesternDigital My Cloud Os<5.10.122
Any of the following
WesternDigital My Cloud Dl2100
WesternDigital My Cloud Dl4100
WesternDigital My Cloud Ex2 Ultra
WesternDigital My Cloud Ex2100
WesternDigital My Cloud Ex4100
WesternDigital My Cloud Mirror Gen 2
WesternDigital My Cloud Pr2100
WesternDigital My Cloud Pr4100
Event History
Mar 10, 2021
CVE Published
via MITRE·04:55 AM
Data Sourced
via MITRE·04:55 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Jun 29, 2026
Advisory Published
via ZDI·04:44 AM
Data Sourced
via ZDI·04:44 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for the Western Digital MyCloud PR4100 Link Resolution Information Disclosure vulnerability?
The vulnerability ID for the Western Digital MyCloud PR4100 Link Resolution Information Disclosure vulnerability is CVE-2021-3310.
2
What is the severity rating of CVE-2021-3310?
The severity rating of CVE-2021-3310 is 7.8 (High).
3
Which software is affected by CVE-2021-3310?
The Western Digital My Cloud OS version up to and exclusive of 5.10.122 is affected by CVE-2021-3310.
4
How can an attacker exploit CVE-2021-3310?
An attacker can exploit CVE-2021-3310 by creating a symbolic link within the SMB and AFP services.
5
Is authentication required to exploit CVE-2021-3310?
No, authentication is not required to exploit CVE-2021-3310.