CVE-2025-30247 affects the Western Digital My Cloud (OS 5) firmware prior to version 5.31.108 on various My Cloud NAS models (PR2100, PR4100, EX4100, EX2 Ultra, Mirror Gen2, DL2100, EX2100, DL4100, and others). Western Digital has released firmware version 5.31.108 to address the issue (September 2025). According to public reports, the vulnerability is classified as a critical OS command injection within the web user interface, which can be triggered via specially crafted HTTP POST requests. A successful attack allows an unauthenticated remote actor to access all stored data, with the ability to encrypt, delete, or modify it.
| Date | 2025-10-06 17:20:15 |
| Information |
|
Technical Summary
This is an OS command injection vulnerability that allows an unauthenticated remote attacker to execute arbitrary system commands on affected My Cloud NAS devices by sending specially crafted HTTP POST requests to the device’s web interface. A successful exploit can lead to full control over the affected NAS devices. The issue affects My Cloud OS5 firmware versions prior to 5.31.108; the firmware provided by the manufacturer 5.31.108 contains the fix.
Recommendations
- Apply the patch immediately — update all affected My Cloud OS5 devices to firmware 5.31.108 or later. Coordinate across the environment and automate where possible.
- Remove public exposure — disable port forwarding or remote access to the device management interface; if remote management is necessary, place access behind a VPN or jump host.
- Network segmentation and access control — isolate NAS devices on a management VLAN, restrict administrative access to specific trusted hosts, and apply restrictive firewall rules.
- Limit outbound access — block or strictly control outbound connections from NAS devices to sensitive addresses (e.g., cloud metadata services such as
169.254.169.254) and internal management APIs to reduce the risk of exfiltration or lateral movement. - Monitor and investigate — observe suspicious POST requests to administrative endpoints, unusual processes or network connections originating from NAS devices, unexpected account or cronjob creation, or signs of data encryption. In case of suspected compromise, isolate the device and collect forensic artifacts before reconstruction.
- Backup and recovery — ensure offline and tested backups exist before remediation; if the appliance is compromised, perform a wipe and rebuild from trusted media after implementing the recovery plan.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
