Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Western Digital

First CVE: Jul 31, 2013Active for: 13 yearsTotal CVEs: 95

Western Digital's vulnerability profile centers on a modest but widely deployed portfolio of network-attached storage and data-management appliances, with the most prominent exposure occurring in products such as the My Cloud EX2 Ultra and DL-series storage systems. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the command-injection, buffer-overflow, authentication, and session-management weaknesses that recur across its firmware and storage-appliance offerings. Defenders should prioritize inventory and patching of exposed storage devices, particularly those accessible from untrusted networks; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
95
Total CVEs
More Total CVEs than 90% of tracked vendors
0.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 90% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Western Digital over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 31, 2013
12 years ago
Most Recent CVE
Jan 26, 2026
179 days ago

Self-Reporting Analysis

Of all the CVEs published by Western Digital as a CNA, 0.0% affect products that Western Digital develops as a vendor.

100.0%
Self-reported: 0 (0.0%)
Third-party: 49 (100.0%)

Of all the CVEs published that affect products developed by Western Digital, 0.0% are self-published by Western Digital as a CNA.

100.0%
Self-published: 0 (0.0%)
Other CNAs: 8 (100.0%)

Products(26 total)

Top CVEs

Signals from CVEs in this vendor scope (95 CVEs).

95 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-10108CRITICAL
Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg parameter in the POST data.
Jan 3, 20179.891NOYES
CVE-2018-17153CRITICAL
It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulne
Sep 18, 20189.889NOYES
CVE-2017-17560CRITICAL
An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload fu
Dec 12, 20179.886NOYES
CVE-2022-29844CRITICAL
A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files. This c
Jan 26, 20239.851NONO
CVE-2018-18472CRITICAL
Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration
Jun 19, 20199.848NONO
CVE-2019-16399CRITICAL
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker ca
Sep 18, 20199.845NOYES
CVE-2016-10107CRITICAL
Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a modified Cookie header.
Jan 3, 20179.837NONO
CVE-2014-2846HIGH
Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary
Apr 28, 20147.536NOYES
CVE-2025-30247CRITICAL
An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system
Sep 29, 20259.334NONO
CVE-2020-25765CRITICAL
Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western Digital My Cloud Devices prior to 5.4.1140.
Oct 27, 20209.833NONO
View all 95 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products95 CVEs
28%
33%
39%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local14 (14.7%)
Network72 (75.8%)
Unknown3 (3.2%)
Physical3 (3.2%)
Adjacent Network3 (3.2%)
Attack Complexity
Low85 (89.5%)
High7 (7.4%)
Unknown3 (3.2%)
User Interaction
None80 (84.2%)
Unknown3 (3.2%)
Required10 (10.5%)
Privileges Required
Low19 (20.0%)
High6 (6.3%)
None67 (70.5%)
Unknown3 (3.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (95 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
3.2% of CVEs· 99th percentile
Nuclei
2 CVEs
2.1% of CVEs· 97th percentile
ExploitDB
4 CVEs
4.2% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Western Digital.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Western Digital — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Western Digital's Products

View all 5 CNAs →

Top CWEs