Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Critical

OS Command Injection in Western Digital My Cloud UI

IdentifiersCVE-2025-30247CWE-78· Improper Neutralization of Special…

CVE-2025-30247 is a critical OS command injection vulnerability in the user interface of Western Digital My Cloud NAS firmware prior to version 5.31.108. The flaw can be triggered by sending a specially crafted HTTP POST request to vulnerable UI endpoints, causing attacker-controlled input to be incorporated into system command execution. Successful exploitation allows a remote attacker to execute arbitrary system commands on the affected NAS device.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can result in remote arbitrary command execution on the NAS device. Western Digital indicates this may lead to unauthorized file access, file modification or deletion, user enumeration, configuration changes, and execution of attacker-supplied binaries. Given the nature of command injection on a NAS appliance, compromise could also enable full device takeover within the privileges of the vulnerable service and facilitate persistence or further lateral activity from the appliance.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, Western Digital recommends taking affected devices offline until they can be updated. The vendor notes that offline My Cloud devices can continue to function as local storage in LAN mode, though cloud-stored files will not be available while offline. For end-of-support models such as My Cloud DL4100 and My Cloud DL2100, no vendor mitigation beyond removing exposure is provided in the available content.

Remediation

Patch, then assume compromise.

Upgrade affected Western Digital My Cloud devices to firmware version 5.31.108 or later. The vendor states that all prior firmware versions on the listed supported My Cloud models are affected. A reboot is required after applying the update, and the device should remain powered during the update process to avoid data corruption. For devices with automatic updates enabled, Western Digital indicated the update began rolling out on September 23, 2025.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity30

Community discussion across Reddit, Mastodon, and other social sources.