CVE-2016-10107: Western Digital Mycloud NAS

Critical severity, CVSS 9.8. EPSS: 11.1% chance of exploitation in the next 30 days.

Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a modified Cookie header.

Affected products

Published 2017-01-03. Last modified 2026-06-17.