logo

Critical WD My Cloud bug allows remote command injection

ID: 5d92cab8-765e-5688-bd5f-895ef6ab9706

STIX ID: report--5d92cab8-765e-5688-bd5f-895ef6ab9706

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-09-30

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

**Western Digital released firmware 5.31.108 to patch CVE-2025-30247, a critical OS command injection in My Cloud NAS devices that allows remote arbitrary command execution via specially crafted HTTP POST requests; multiple consumer models are impacted and some end-of-support units may not receive updates, so affected users should apply the update or take devices offline until remediated.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.