Home

Description

An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system commands via a specially crafted HTTP POST.

PUBLISHED Reserved 2025-03-19 | Published 2025-09-29 | Updated 2025-09-30 | Assigner WDC PSIRT




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Product status

Default status
unaffected

Any version before 5.31.108
affected

Credits

Western Digital would like to thank w1th0ut for reporting this reporter

References

www.westerndigital.com/...al-my-cloud-os-5-firmware-5-31-108

cve.org (CVE-2025-30247)

nvd.nist.gov (CVE-2025-30247)

Download JSON