An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system commands via a specially crafted HTTP POST.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
To take advantage of the latest security fixes, Western Digital recommends that users promptly update their devices to the latest firmware by clicking on the firmware update notification.
References
History
Mon, 29 Sep 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system commands via a specially crafted HTTP POST. | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: WDC PSIRT
Published:
Updated: 2025-09-29T21:07:20.786Z
Reserved: 2025-03-19T16:24:18.441Z
Link: CVE-2025-30247

No data.

Status : Received
Published: 2025-09-29T21:15:33.587
Modified: 2025-09-29T21:15:33.587
Link: CVE-2025-30247

No data.

No data.