Western Digital's vulnerability profile centers on a modest but widely deployed portfolio of network-attached storage and data-management appliances, with the most prominent exposure occurring in products such as the My Cloud EX2 Ultra and DL-series storage systems. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the command-injection, buffer-overflow, authentication, and session-management weaknesses that recur across its firmware and storage-appliance offerings. Defenders should prioritize inventory and patching of exposed storage devices, particularly those accessible from untrusted networks; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Western Digital over time
Of all the CVEs published by Western Digital as a CNA, 0.0% affect products that Western Digital develops as a vendor.
Of all the CVEs published that affect products developed by Western Digital, 0.0% are self-published by Western Digital as a CNA.
Signals from CVEs in this vendor scope (95 CVEs).
95 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10108CRITICAL Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg parameter in the POST data. | Jan 3, 2017 | 9.8 | 91 | NO | YES |
CVE-2018-17153CRITICAL It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulne | Sep 18, 2018 | 9.8 | 89 | NO | YES |
CVE-2017-17560CRITICAL An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload fu | Dec 12, 2017 | 9.8 | 86 | NO | YES |
CVE-2022-29844CRITICAL A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files. This c | Jan 26, 2023 | 9.8 | 51 | NO | NO |
CVE-2018-18472CRITICAL Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration | Jun 19, 2019 | 9.8 | 48 | NO | NO |
CVE-2019-16399CRITICAL Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker ca | Sep 18, 2019 | 9.8 | 45 | NO | YES |
CVE-2016-10107CRITICAL Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a modified Cookie header. | Jan 3, 2017 | 9.8 | 37 | NO | NO |
CVE-2014-2846HIGH Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary | Apr 28, 2014 | 7.5 | 36 | NO | YES |
CVE-2025-30247CRITICAL An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system | Sep 29, 2025 | 9.3 | 34 | NO | NO |
CVE-2020-25765CRITICAL Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western Digital My Cloud Devices prior to 5.4.1140. | Oct 27, 2020 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (95 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Western Digital.
Media articles that mention a CVE ID that affects a product developed by Western Digital — matched by CVE ID, not by vendor name.