External risk intelligence

Western Digital My Cloud OS 5 Command Injection

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-30247

The vulnerability exists in the user interface of Western Digital My Cloud NAS devices. These products are commonly deployed as network-attached storage units with web-based management interfaces that are frequently exposed to the internet to facilitate remote access and file management features for users, making the web interface a common internet-facing attack surface.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the user interface of Western Digital My Cloud network-attached storage devices, potentially allowing remote attackers to execute system commands without authentication. This issue affects the device's ability to manage and secure data.

  • Attackers can run commands remotely.
  • Impacts data access and device control.
  • Confirm relevance and exposure of devices.

Attack Path

How an attacker could exploit the issue

Attackers can target the user interface of Western Digital My Cloud NAS devices, which often have web-based management portals accessible from the internet. By sending a specially crafted HTTP POST request, an attacker could exploit a vulnerability in this interface to execute arbitrary system commands.

  • No authentication or special privileges needed.
  • Exploited via crafted HTTP POST request.
  • Allows arbitrary system command execution.

Live Threat

Current exploitation, exposure, and threat context

Remote attackers could execute arbitrary system commands on affected NAS platforms by sending a specially crafted HTTP POST request through the user interface, potentially leading to unauthorized system access and modification.

  • System command execution on NAS.
  • Via specially crafted HTTP POST request.
  • Unauthorized system access and modification.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability likely impacts users of Western Digital My Cloud NAS devices. Initial steps should focus on identifying affected devices, assessing their exposure and business criticality, locating the accountable owner, and then prioritizing remediation based on risk. Coordination with the vendor for firmware updates or alternative mitigations will be key.

  • Identify affected NAS devices.
  • Verify remote accessibility and criticality.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Western Digital My Cloud and how is it used?

Western Digital My Cloud devices are Network-Attached Storage (NAS) units. They function as centralized private clouds, allowing users to store, back up, and remotely access large volumes of personal or business data across a network.

What does CWE-78 mean for CVE-2025-30247?

This vulnerability is an OS command injection (CWE-78). It means the software does not properly filter user-supplied data before passing it to the underlying operating system. Because of this, an attacker can input specific commands that the device interprets as legitimate system instructions.

How does an attacker trigger CVE-2025-30247?

An attacker triggers this flaw by sending a specially crafted HTTP POST request to the device's user interface. Simply navigating to the site or sending standard, non-malicious traffic does not trigger the vulnerability; it requires the specific, manipulated data structure designed to exploit the injection point.

Do I need to worry if my device is on the internet?

Yes, if you use the web-based management interface. Halo Surface Signal identifies these NAS devices as having a high likelihood of being internet-facing to support remote access. Because the flaw exists in the user interface, any device reachable from the public internet is at a higher risk of being targeted.

What should I do first to secure my NAS?

Start by identifying your specific device model and firmware version. Confirm if your My Cloud NAS is running software older than version 5.31.108. If so, contact the vendor to obtain and apply the latest firmware update, as this is the primary path to patching the vulnerability.

References