Western Digital's cloud storage devices are still vulnerable to security flaws, despite patches issued to resolve the bugs, the company said in a blog post. The company said future updates to fix the affected products, although it's unclear how many issues are still outstanding.
Vulnerabilities were discovered in 12 WD devices and described for the first time in a blog post by the security company GulfTech. GulfTech noted that a series of WD devices allow remote back door access, via the username “mydlinkBRionyg” and the password “abc12345cba”. GulfTech also describes a file upload flaw within the devices that would allow potential hackers to gain remote access. In addition, the devices are also susceptible to command injection issues, denial of service attacks and information dumps.
The GulfTech contacted Western Digital regarding the vulnerabilities last June and the company requested 90 days until its full disclosure. It released some firmware updates for devices in November to resolve “critical security vulnerabilities that allowed unauthorized file deletion, illegal command execution and identity bypass.” However the GulfTech post states that it has not tested the Western Digital patches that have been released and notes that users report that “some vulnerabilities still remain.”.
To stay safe, WD says that My Cloud owners should disable access to the Cloud Dashboard and disable port forwarding features. The company says that a future updated version will address device exploitation by a hacker with access to the owner's local network or if the user has enabled certain My Cloud settings. “Western Digital is constantly working to improve the capability and security of our products, including community research to address issues they may discover”, the company said.
The storage devices that are connected to the Western Digital My Cloud (NAS) network allow users to store files locally and access them over the internet. These devices are primarily used in homes and small businesses. The models that currently offer access to the Dashboard's Cloud Access and are affected by the vulnerability include:
My Cloud EX2
My Cloud EX4
My Cloud EX2100
My Cloud EX4100
My Cloud EX2 Ultra
My Cloud DL2100
My Cloud DL4100
My Cloud PR2100
My Cloud PR4100
My Cloud Mirror
My Cloud Mirror Gen 2
