CVE-2025-30247 — OS Command Injection in Digital MY Cloud
Severity
9.3CRITICALNVD
EPSS
1.7%
top 17.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 29
Description
An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system commands via a specially crafted HTTP POST.
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Packages1 packages
🔴Vulnerability Details
1GHSA▶
GHSA-6cxq-rrcr-rpxc: An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5↗2025-09-29