Western Digital has released security updates for a critical vulnerability affecting many My Cloud NAS.
See also: Rsync vulnerabilities allow complete control of servers

The vulnerability, tracked as CVE-2025-30247, could allow a remote attacker to execute arbitrary code on vulnerable systems, potentially leading to complete device takeover.
The company addressed the high-severity issue in My Cloud firmware version 5.31.108, released on September 24, 2025.
A successful exploitation of this remote code execution (RCE) vulnerability would allow an unauthenticated attacker to compromise the security of the My Cloud NAS device. This could lead to data theft, malware or ransomware deployment, or the compromised device being integrated into a botnet for use in further attacks.
Given that NAS devices often store sensitive personal and business data, the impact of such a breach could be severe.
See also: Vulnerability in D-Link Routers allows complete control of the router

Western Digital has strongly urged all users to promptly update their devices to the latest firmware to mitigate the threat. The update can be applied directly via the firmware update notification in the device's management interface.
The advisory credits security researcher w1th0ut for discovering and responsibly reporting the vulnerability, allowing the company to develop and issue a fix.
The security update is critical for a wide range of My Cloud NAS products. Western Digital has confirmed that the following devices are affected and should be updated to firmware version 5.31.108 or later to protect against CVE-2025-30247:
– My Cloud Mirror Gen 2
– My Cloud WDBCTLxxxxxx-10
This incident highlights the ongoing security risks associated with internet-connected storage devices. Malicious actors often scan and target unpatched NAS systems due to the valuable data they contain.
See also: D-Link: Hackers exploit vulnerability affecting EOL NAS devices

The security update application once available is one of the most effective measures users can take to protect their data from unauthorized access and cyber attacks. It is recommended that users check their device settings and ensure that automatic updates are enabled wherever possible to maintain security.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
