WD My Cloud Devices Reportedly Vulnerable to Remote Attacks

Advertisement
By Shekhar Thakran | Updated: 7 March 2017 13:47 IST
Highlights
  • Western Digital has already fixed one severe bug with update
  • Exploitee.rs says it released bugs early due to WD's industry reputation
  • Hackers can potentially upload files without user permission

If you are a proud owner of a WD My Cloud NAS device, it's time to pay attention. The company's My Cloud NAS devices have been found vulnerable to remote hacking via the Internet and can potentially allow hackers to get access to your account and even upload files without permission.

As per Exploitee.rs, due to poorly implemented scripts on the WD My Cloud drives, hackers could bypass the login as its function makes use of cookies that could be provided by the hacker in order to gain access, as pointed out in a report by Engadget. "It is important to note that all commands executed through the web interface are done so as the user the web-server is running as, which, in this case is root," Exploitee.rs said in its post.

Although the login bypass bug has been fixed by the company with a software update, Exploitee.rs claims the fix introduced another bug. This, along with other security flaws have been published by the Exploitee.rs team even before they have been patched supposedly to force Western Digital into taking action.

Advertisement

The devices in question regarding the security flaws include WD My Cloud Gen 2, My Cloud Mirror, My Cloud PR2100, My Cloud PR4100, My Cloud EX2 Ultra, My Cloud EX2, My Cloud EX4, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, and My Cloud DL4100.

Advertisement

Exploitee.rs says that usually the team works with the vendors to ensure that the fixes are released properly for the flaws, however, Western Digital's "reputation within the community" made the team publish the flaws to public right away. The team says that as WD has developed a reputation for ignoring the severity of the bugs reported to it, they are trying to "alert the community of the flaws" so that users can limit access of their WD My Cloud devices to the Internet as much as possible.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Starlink Will Offer Unlimited Satellite Internet in India at This Price
  2. Realme Narzo 90 Series 5G India Launch Announced
  3. Be Dune Teen OTT Release: When, Where to Watch the Marathi Comedy Drama
  4. Motorola Edge 70 With 5.99mm Slim Profile Will Launch in India on This Date
  5. iPhone 16 Deal Alert: Get It for Just Rs 65,900 Effective Price
  6. New Shortcut Lets Scientists Run Complex Quantum Models on a Laptop
  7. Xiaomi India COO Talks About Next Redmi Note, AI, and IoT Strategy
  8. Battlefield 6's Next Season 1 Update Arrives This Week: All You Need to Know
  9. OpenAI Says ChatGPT Isn't Showing Ads to Paid Users
  1. Motorola Edge 70 India Launch Date Announced; Confirmed to Feature Triple 50-Megapixel Camera Setup
  2. Battlefield 6's 'Winter Offensive' Update Launches This Week With New Content, Audio Improvements and More
  3. Chinese Brands Aiming to Win Users with AI Features That Apple Lacks: Report
  4. Samsung Ballie Robot Reportedly Delayed Again, Won't Launch This Year
  5. Vivo S50, Vivo S50 Pro Mini Launch Date Announced; Colour Options Revealed
  6. Starlink Subscription Price in India Revealed as Elon Musk-Led Firm Prepares for Imminent Launch
  7. Google Releases Gemini 3 Deep Think Model to Its Most Expensive Subscription Tier
  8. Meta’s Phoenix Mixed Reality Smart Glasses Reportedly Delayed; Could Finally Launch in 2027
  9. iPhone 16 Deal Alert: Get It for Just Rs 65,900 Effective Price
  10. OpenAI Clarifies It Isn’t Testing Ads on ChatGPT Despite User Claims
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.