An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system commands via a specially crafted HTTP POST.
History

Tue, 30 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Sep 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Western Digital
Western Digital my Cloud
Vendors & Products Western Digital
Western Digital my Cloud

Mon, 29 Sep 2025 21:15:00 +0000

Type Values Removed Values Added
Description An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system commands via a specially crafted HTTP POST.
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WDC PSIRT

Published:

Updated: 2025-09-30T14:56:37.134Z

Reserved: 2025-03-19T16:24:18.441Z

Link: CVE-2025-30247

cve-icon Vulnrichment

Updated: 2025-09-30T14:56:34.707Z

cve-icon NVD

Status : Received

Published: 2025-09-29T21:15:33.587

Modified: 2025-09-29T21:15:33.587

Link: CVE-2025-30247

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-30T08:47:53Z