CVE-2016-10108: Western Digital Mycloud NAS

Critical severity, CVSS 9.8. EPSS: 97.8% chance of exploitation in the next 30 days.

Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg parameter in the POST data.

Affected products

Published 2017-01-03. Last modified 2026-06-17.