An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system commands via a specially crafted HTTP POST.
Fixes

Solution

No solution given by the vendor.


Workaround

To take advantage of the latest security fixes, Western Digital recommends that users promptly update their devices to the latest firmware by clicking on the firmware update notification.

History

Mon, 29 Sep 2025 21:15:00 +0000

Type Values Removed Values Added
Description An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system commands via a specially crafted HTTP POST.
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WDC PSIRT

Published:

Updated: 2025-09-29T21:07:20.786Z

Reserved: 2025-03-19T16:24:18.441Z

Link: CVE-2025-30247

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-29T21:15:33.587

Modified: 2025-09-29T21:15:33.587

Link: CVE-2025-30247

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.