CVE-2025-30247OS Command Injection in Digital MY Cloud

Severity
9.3CRITICALNVD
EPSS
1.7%
top 17.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 29

Description

An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system commands via a specially crafted HTTP POST.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages1 packages

CVEListV5western_digital/my_cloud< 5.31.108

🔴Vulnerability Details

1
GHSA
GHSA-6cxq-rrcr-rpxc: An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 52025-09-29