Western Digital has addressed a critical security vulnerability, tracked as CVE-2025-30247, affecting its My Cloud network-attached storage (NAS) devices. This flaw is an OS command injection vulnerability present in the firmware’s user interface, which allows remote attackers to execute arbitrary system commands by sending specially crafted HTTP POST requests. The vulnerability is notable for not requiring any prior authentication or user interaction, making exploitation straightforward for remote attackers. Successful exploitation could result in full system compromise, granting attackers access to all data stored on the affected NAS device, with the potential to encrypt, delete, or modify files. Additionally, a compromised device could serve as a launchpad for further attacks against other systems on the same network, increasing the risk to both home and small business environments where these devices are commonly deployed. The vulnerability affects My Cloud firmware versions prior to v5.31.108, which was released on September 23, 2025. Impacted models include My Cloud PR2100, PR4100, EX2 Ultra, EX4100, Mirror Gen 2, EX2100, DL2100, DL4100, WDBCTLxxxxxx-10, and My Cloud. Western Digital has urged all users to promptly update their devices to the latest firmware to mitigate the risk, noting that devices with automatic updates enabled should already be protected unless disconnected or powered off. The vulnerability was privately reported by a security researcher, and as of the latest reports, there is no evidence of exploitation in the wild. The CVSS score for this vulnerability is 9.3, reflecting its critical severity and the ease with which it can be exploited remotely. Security advisories emphasize the importance of immediate action, as unpatched devices remain highly vulnerable to remote compromise. The flaw underscores the ongoing risks associated with network-connected storage devices, particularly those exposed to the internet or used in environments with sensitive data. Western Digital’s response has included direct notifications to users and detailed instructions for applying the necessary firmware updates. The company’s Product Security Incident Response Team (PSIRT) has been credited as the source of the official advisory. Organizations and individuals using affected My Cloud NAS devices are strongly advised to verify their firmware version and apply updates without delay to prevent potential breaches. The incident highlights the critical need for timely patch management and the risks posed by unauthenticated remote code execution vulnerabilities in widely deployed storage solutions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Western Digital urged customers to immediately install the patched firmware or disconnect affected devices from the internet until they can be updated. The advisory also noted that My Cloud DL4100 and DL2100 are end-of-support and did not include mitigation guidance for those models.
Western Digital released firmware version 5.31.108 to fix CVE-2025-30247 on supported My Cloud models, with all prior versions affected. The company said the bug could enable unauthorized file access, deletion, configuration changes, user enumeration, or binary execution.
A security researcher using the alias “w1th0ut” reported CVE-2025-30247, a critical OS command injection vulnerability in Western Digital My Cloud NAS devices. The flaw affects the My Cloud user interface and can be triggered via crafted HTTP POST requests to execute arbitrary system commands.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityonline.info
Open sourcebleepingcomputer.com
Open sourcehelpnetsecurity.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.