Western Digital's vulnerability profile centers on a moderate but widely deployed portfolio of network-attached storage (NAS) systems, particularly its My Cloud line of products spanning both small-business and enterprise tiers. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through weakness classes including OS command injection, improper authentication, path traversal, and insufficiently protected credentials—exposures that are characteristic of appliances combining web interfaces, remote-access capabilities, and local storage management. The concentration of these flaws across flagship products such as the My Cloud PR and EX series reflects the authentication and input-validation demands of internet-facing storage devices that often sit behind a security perimeter but remain targets for lateral movement and credential compromise. Defenders should prioritize inventory and patching of affected NAS appliances, particularly those exposed to untrusted networks, and monitor for authentication bypass and command-injection exploits in this device class. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Westerndigital over time
Signals from CVEs in this vendor scope (95 CVEs).
95 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10108CRITICAL Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg parameter in the POST data. | Jan 3, 2017 | 9.8 | 91 | NO | YES |
CVE-2018-17153CRITICAL It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulne | Sep 18, 2018 | 9.8 | 89 | NO | YES |
CVE-2017-17560CRITICAL An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload fu | Dec 12, 2017 | 9.8 | 86 | NO | YES |
CVE-2022-29844CRITICAL A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files. This c | Jan 26, 2023 | 9.8 | 51 | NO | NO |
CVE-2018-18472CRITICAL Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration | Jun 19, 2019 | 9.8 | 48 | NO | NO |
CVE-2019-16399CRITICAL Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker ca | Sep 18, 2019 | 9.8 | 45 | NO | YES |
CVE-2016-10107CRITICAL Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a modified Cookie header. | Jan 3, 2017 | 9.8 | 37 | NO | NO |
CVE-2014-2846HIGH Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary | Apr 28, 2014 | 7.5 | 36 | NO | YES |
CVE-2025-30247CRITICAL An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system | Sep 29, 2025 | 9.3 | 34 | NO | NO |
CVE-2020-25765CRITICAL Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western Digital My Cloud Devices prior to 5.4.1140. | Oct 27, 2020 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (95 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Westerndigital.
Media articles that mention a CVE ID that affects a product developed by Westerndigital — matched by CVE ID, not by vendor name.