Article Details
Retrieved on: 2025-09-30 15:08:49
Tags for this article:
Click the tags to see associated articles and topics
Summary
Western Digital has released critical firmware updates to address CVE-2025-30247, a severe command injection vulnerability affecting multiple My Cloud NAS models that allows remote attackers to execute arbitrary system commands.
The security flaw impacts nine My Cloud models and can be exploited through malicious HTTP POST requests to vulnerable endpoints. Successful exploitation could lead to unauthorized file access, data modification, user enumeration, or complete system compromise. The vulnerability poses significant risks as hackers have previously used similar NAS flaws to harvest sensitive data, build botnets, or deploy ransomware.
Article found on: www.bleepingcomputer.com
This article is found inside other hiswai user's workspaces. To start your own collection, sign up for free.
Sign UpAlready have an account? Log in here