CVE-2019-9951: Western Digital My Cloud DL2100
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an unauthenticated file upload vulnerability. The page web/jquery/uploader/uploadify.php can be accessed without any credentials, and allows uploading arbitrary files to any location on the attached storage.
Affected products
- Western Digital My Cloud DL2100: before 2.31.174 (fixed in 2.31.174)
- Western Digital My Cloud DL4100 Firmware: before 2.31.174 (fixed in 2.31.174)
- Western Digital My Cloud EX2100 Firmware: before 2.31.174 (fixed in 2.31.174)
- Western Digital My Cloud EX2 Ultra Firmware: before 2.31.174 (fixed in 2.31.174)
- Western Digital My Cloud EX4100: before 2.31.174 (fixed in 2.31.174)
- Western Digital My Cloud Firmware: before 2.31.174 (fixed in 2.31.174)
- Western Digital My Cloud Mirror Gen 2 Firmware: before 2.31.174 (fixed in 2.31.174)
- Western Digital My Cloud PR2100 Firmware: before 2.31.174 (fixed in 2.31.174)
- Western Digital My Cloud PR4100: before 2.31.174 (fixed in 2.31.174)
Published 2019-04-24. Last modified 2026-06-17.