WD NAS Devices Vulnerable to Attacks Due to a Zero-Day Flaw That's Yet to Be Officially Fixed

WD released My Cloud OS 5 instead of fixing the zero-day vulnerability that exists in its My Cloud OS 3.

Advertisement
By Jagmeet Singh | Updated: 6 July 2021 11:35 IST
Highlights
  • WD devices on My Cloud OS 3 could easily be targeted by attackers
  • The zero-day vulnerability was fixed on My Cloud OS 5
  • My Cloud OS 5 is, however, not yet provided to all WD users

Many WD users on its NAS devices appear to be affected by the zero-day vulnerability

Photo Credit: WD

Western Digital (WD) devices running My Cloud OS 3 have been found to be vulnerable due to the existence of a zero-day flaw. The new security loophole, which was discovered by security researchers, has come into the limelight just days after another serious vulnerability led to some users having their data wiped from WD My Book Live devices. WD quietly mitigated the issue impacting its storage units running My Cloud OS 3 by releasing My Cloud OS 5 last year. However, the vulnerability can still result in a major impact as a large number of WD network-attached storage (NAS) devices are yet to be updated to the latest operating system.

The zero-day vulnerability affecting My Cloud OS 3 was discovered by security researchers Pedro Ribeiro and Radek Domanski. Both researchers made a video, which is available on YouTube, to detail the issue that essentially allows attackers to remotely update the firmware on a vulnerable device using backdoor access, as reported by KrebsOnSecurity. The vulnerability could be exploited using a user account that carries a blank password.

According to the researchers, the vulnerability affects most of the WD NAS lineup, though the devices running My Cloud OS 5 are unaffected as the new cloud-based operating system fixed the loophole. WD also mentioned on its support page that it wouldn't provide any security updates to the My Cloud OS 3 firmware and recommends users to move to My Cloud OS 5.

Advertisement

However, it is important to point out that My Cloud OS 5 comes as a complete rewrite of the company's operating system designed for NAS devices. This means that it doesn't carry all the features that were available on My Cloud OS 3. The newer version also doesn't support remote storage access on older devices, including the ones running on Windows 7, Android 4.0, and iOS 8.0.

Advertisement

The limited feature availability on My Cloud OS 5 may have restricted some users to continue to use the older (read vulnerable) operating system on their devices. Also, it is important to note that the new operating system doesn't support hardware such as the WD My Book Live, My Book Live Duo, WD TV Live Hub, and the My Net N900c. It is also not yet available for a list of WD devices, including the My Cloud, My Cloud EX2, My Cloud EX4, and the My Cloud Mirror.

Some of the users who tried to move to My Cloud OS 5 last year also reported that the update bricked their devices.

Advertisement

With all these limitations and problems, it is currently unclear how many users have actually switched to the latest operating system and are not affected by the zero-day vulnerability. WD has provided steps to upgrade to My Cloud OS 5 through a support page, but that will not be of any use for people on unsupported hardware or who want to get all the features that they were using on My Cloud OS 3.

Having said that, the researchers who discovered the flaw have developed and released their own patch to fix the loophole they found in My Cloud OS 3. WD noted that it was aware of third parties offering security patches for its older hardware. “We have not evaluated any such patches and we are unable to provide any support for such patches,” it said.

Advertisement

The scope of the new zero-day vulnerability could be as wide as the one affected WD My Book Live users last month. However, the company is yet to confirm whether it has any fixes in the works.

Gadgets 360 has reached out to WD for a comment on the new vulnerability and will update this space when the company responds.


Windows 11 has been unveiled, but do you need it? We discussed this on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Top OTT Releases of the Week: Kantara Chapter 1, Lokah Chapter 1, Idli Kadai, and More
  2. iQOO 15 Indian Variant Allegedly Surfaces on Geekbench Ahead of Launch
  3. Realme GT 8 Pro India Launch Date Leaked: Here's When It Might Arrive
  4. Starlink Is Hiring for Multiple Roles in Bengaluru Ahead of Launch in India
  1. SpaceX Revises Artemis III Moon Mission with Simplified Starship Design
  2. Rare ‘Second-Generation’ Black Holes Detected, Proving Einstein Right Again
  3. Starlink Hiring for Payments, Tax and Accounting Roles in Bengaluru as Firm Prepares for Launch in India
  4. Google's 'Min Mode' for Always-on Display Mode Spotted in Development on Android 17: Report
  5. OpenAI Upgrades Sora App With Character Cameos, Video Stitching and Leaderboard
  6. Samsung's AI-Powered Priority Notifications Spotted in New One UI 8.5 Leak
  7. Samsung Galaxy S26 Series Could Feature Model Slimmer Than Galaxy S25 Edge With New Name
  8. iQOO 15 Colour Options Confirmed Ahead of November 26 India Launch: Here’s What We Know So Far
  9. Vivo X300 to Be Available in India-Exclusive Red Colourway, Tipster Claims
  10. OpenAI Introduces Aardvark, an Agentic Security Researcher That Can Find and Fix Vulnerabilities
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.