Running one of Western Digitals My-cloud products? -read this… and update your firmware.
Affected My Cloud Firmware Versions and Models
Western Digital’s My Cloud and My Cloud Mirror firmware version 2.30.165 and earlier are affected by all above-reported vulnerabilities.
Affected device models include My Cloud Gen 2, My Cloud PR2100, My Cloud PR4100, My Cloud EX2 Ultra, My Cloud EX2, My Cloud EX4, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100 and My Cloud DL4100.
Metasploit modules for all the vulnerabilities have been released online.
#westerndigital #mycloud #security
Originally shared by The Hacker News
✓ Unrestricted File Upload (Shell as Root)
✓ Secret Hardcoded Root Backdoor Account
✓ CSRF, Command Injection, DoS
✓ NOT PATCHED Even 6 Months After Reporting