CVE-2025-30247: Western Digital My Cloud
Critical severity, CVSS 9.3. EPSS: 1.1% chance of exploitation in the next 30 days.
An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system commands via a specially crafted HTTP POST.
Affected products
- Western Digital My Cloud: before 5.31.108 (fixed in 5.31.108)
Published 2025-09-29. Last modified 2026-10-09.