Western Digital has released firmware updates for multiple My Cloud NAS models to patch a critical-severity vulnerability that could be exploited remotely to execute arbitrary system commands. Tracked as CVE-2025-30247, the flaw is an OS command injection in the user interface of My Cloud and can be leveraged through specially crafted HTTP POST requests sent to vulnerable endpoints. The vulnerability was reported to Western Digital by a security researcher using the alias “w1th0ut.” The storage device maker released firmware version 5.31.108 to address the issue that impacts all previous versions for the following models: It is worth noting that two of the devices, My Cloud DL4100 and My Cloud DL2100, have reached end of support (EoS) and updates may not be available, as the security advisory from the company does not provide mitigation action for EoS products. My Cloud is Western Digital’s network-attached storage (NAS) are typically used by small businesses, home offices, and individuals that want to store data on a personal cloud and access it from any device. While not intended for use in critical or enterprise environments, they are popular among the general consumer audience for providing easy remote access to files via mobile apps or browsers, media streaming, and automated backups. Exploitation of CVE-2025-30247 to run shell commands could result in unauthorized file access, modification, deletion, user enumeration, configuration changes, or even binary execution. In...
Critical WD My Cloud bug allows remote command injection
BleepingComputer
·Bill Toulas
·Published Sep 30, 2025
·Updated
Affected Software
4 affected components
Western Digital My Cloud=5.31.108
Western Digital My Cloud
Western Digital My Cloud DL4100
Western Digital My Cloud DL2100
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical security vulnerability in Western Digital My Cloud NAS devices that allows for remote command injection.
2
What is CVE-2025-30247?
CVE-2025-30247 is the identifier for the critical vulnerability that enables remote execution of arbitrary system commands on affected WD My Cloud devices.
3
What types of devices are affected by this vulnerability?
The vulnerability impacts various models of Western Digital My Cloud NAS devices, including My Cloud, My Cloud DL4100, and My Cloud DL2100.
4
What should users do to protect their devices?
Users are advised to update their firmware to the latest version to mitigate the security risks associated with this vulnerability.
5
What potential risks does the vulnerability pose?
The flaw could allow remote attackers to execute arbitrary commands, potentially leading to unauthorized access or control over affected devices.