Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Westerndigital

First CVE: Jul 31, 2013Active for: 13 yearsTotal CVEs: 95
47.3
VTI Score
High

Western Digital's vulnerability profile centers on a moderate but widely deployed portfolio of network-attached storage (NAS) systems, particularly its My Cloud line of products spanning both small-business and enterprise tiers. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through weakness classes including OS command injection, improper authentication, path traversal, and insufficiently protected credentials—exposures that are characteristic of appliances combining web interfaces, remote-access capabilities, and local storage management. The concentration of these flaws across flagship products such as the My Cloud PR and EX series reflects the authentication and input-validation demands of internet-facing storage devices that often sit behind a security perimeter but remain targets for lateral movement and credential compromise. Defenders should prioritize inventory and patching of affected NAS appliances, particularly those exposed to untrusted networks, and monitor for authentication bypass and command-injection exploits in this device class. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
95
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
8.0
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Westerndigital over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 31, 2013
12 years ago
Most Recent CVE
Jan 26, 2026
180 days ago

Products(194 total)

Top CVEs

Signals from CVEs in this vendor scope (95 CVEs).

95 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-10108CRITICAL
Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg parameter in the POST data.
Jan 3, 20179.891NOYES
CVE-2018-17153CRITICAL
It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulne
Sep 18, 20189.889NOYES
CVE-2017-17560CRITICAL
An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload fu
Dec 12, 20179.886NOYES
CVE-2022-29844CRITICAL
A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files. This c
Jan 26, 20239.851NONO
CVE-2018-18472CRITICAL
Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration
Jun 19, 20199.848NONO
CVE-2019-16399CRITICAL
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker ca
Sep 18, 20199.845NOYES
CVE-2016-10107CRITICAL
Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a modified Cookie header.
Jan 3, 20179.837NONO
CVE-2014-2846HIGH
Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary
Apr 28, 20147.536NOYES
CVE-2025-30247CRITICAL
An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system
Sep 29, 20259.334NONO
CVE-2020-25765CRITICAL
Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western Digital My Cloud Devices prior to 5.4.1140.
Oct 27, 20209.833NONO
View all 95 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products95 CVEs
28%
33%
39%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local14 (14.7%)
Network72 (75.8%)
Unknown3 (3.2%)
Physical3 (3.2%)
Adjacent Network3 (3.2%)
Attack Complexity
Low85 (89.5%)
High7 (7.4%)
Unknown3 (3.2%)
User Interaction
None80 (84.2%)
Unknown3 (3.2%)
Required10 (10.5%)
Privileges Required
Low19 (20.0%)
High6 (6.3%)
None67 (70.5%)
Unknown3 (3.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (95 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
3.2% of CVEs· 97th percentile
Nuclei
2 CVEs
2.1% of CVEs· Bottom 1%
ExploitDB
4 CVEs
4.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Westerndigital.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Westerndigital — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Westerndigital's Products

View all 5 CNAs →

Top CWEs