CVE-2025-30247 CRITICAL

CVE-2025-30247

Vendor Western Digital
Product My Cloud
Weakness CWE-78
Published September 29, 2025
Last update September 30, 2025

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system commands via a specially crafted HTTP POST.

Key dates

02Disclosure timeline

September 29, 2025 CVE published
September 30, 2025 Record updated