logo

Exploiting Cloud Connectivity to PWN your NAS: WD PR4100

ID: 41b82678-c22f-5173-829a-90f1b75964e3

STIX ID: report--41b82678-c22f-5173-829a-90f1b75964e3

Feed Name: Claroty Team82

Threat Score
90/100

Date Published: 2023-10-18

Date Updated: 2026-04-17

Author: Noam Moshe

...
...

Team82 reports multiple critical vulnerabilities in Western Digital My Cloud OS5 that allowed large-scale enumeration of cloud-connected NAS devices (via certificate harvesting and CT logs), impersonation of devices using publicly-leaked GUIDs to hijack cloud tunnels and steal user JWTs, and a chained file-write plus reboot issue leading to remote code execution; Western Digital has since issued firmware updates and restricted unpatched devices from connecting to the cloud.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.