Western Digital My Cloud Devices Still Have Vulnerabilities, Fixes Promised in Future Updates

Advertisement
By Jagmeet Singh | Updated: 12 January 2018 19:02 IST
Highlights
  • Western Digital My Cloud Received initial fixes last year
  • Security firm GulfTech spotted the vulnerabilities
  • Western Digital is planning fixes through future updates

Despite releasing some initial fixes a couple of months back, it has now been confirmed that Western Digital hasn't addressed all the vulnerabilities exist in its My Cloud storage devices. The company has instead planned some future updates to patch the security loopholes spotted in as many as 12 of its devices.

Security firm GulfTech originally found the vulnerabilities last year that allow remote backdoor admin access through the username "mydlinkBRionyg" and password "abc12345cba". The affected devices were also spotted to have a flaw that would let potential attackers gain remote access through a file upload action. Similarly, the researchers at GulfTech found that the My Cloud devices in question are also vulnerable to security issues such as cross-site request forgery, command injection, denial of service (DoS), and information disclosure.

After getting the reaching of the vulnerabilities exist in the affected devices, GulfTech in June last year intimated Western Digital that eventually resulted in the release of some firmware updates in November. However, the security firm in an advisory to its blog post reveals that some key vulnerabilities still remain.

Advertisement

Western Digital, on its part, recommends that My Cloud users should disable the Dashboard Cloud Access and turn off the additional port-forwarding functionalities to overcome the issue. These workarounds are importantly valid only for the issue that enables a hacker to access to the owner's local network by exploiting the default settings or through gaining a backdoor access via Dashboard Cloud Access, which is available on devices, including My Cloud EX2, My Cloud EX4, My Cloud EX2100, My Cloud EX4100, My Cloud EX2 Ultra, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100, My Cloud PR4100, My Cloud Mirror, and My Cloud Mirror Gen 2. Nevertheless, we can expect fixes for all the issues exist in the My Cloud family through some future updates.

Advertisement

In the meanwhile, Western Digital is reminding its users to ensure the presence of up to date firmware on their devices and enable automatic updates. The users are also urged to implement "sound data protection practices" such as regular data backs and password protection to continue to get a secured experience. "Western Digital works continuously to improve the capability and security of our products, including with the security research community to address issues they may uncover. We encourage responsible disclosure by customers and researchers to ensure our customers are protected while we address valid vulnerabilities," the company writes in a blog post.

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Phone 4a, Phone 4a Pro Launched in India at This Price
  2. OnePlus 15T Confirmed to Launch With a Larger Battery, Faster Charging
  3. Vivo T5x 5G AnTuTu Score Exceeds 1 Million Points, Will Launch in India Soon
  4. Nothing Phone 4a vs Motorola Edge 70: Price in India, Features Compared
  5. Moto Watch Review: The Best Smartwatch Under Rs. 6,000 in 2026?
  6. Realme Narzo Power 5G With 10,001mAh Battery Launched in India: Price, Specifications
  7. Samsung Galaxy A47 5G, Galaxy A57 5G Specifications Leak Ahead of Launch
  8. Nothing Launches Headphone (a) With Adaptive ANC, Spatial Audio Support
  9. The OnePlus 15T is expected to go official in China soon as the latest addition to the One
  10. Nothing Phone 4a Pro First Impressions
  1. OnePlus 15T Tipped to Feature 1.5K 165Hz Display as Company Confirms Key Specifications
  2. Samsung Galaxy A37 5G and Galaxy A57 5G Specifications Reportedly Leaked in Full Ahead of Launch
  3. ISS Crew Prepares to Send Japan’s HTV-X1 Cargo Spacecraft Back to Earth After Four Months
  4. OpenAI’s Codex App Is Now Available on Windows, Can Be Downloaded via Microsoft Store
  5. OpenAI Teases GPT-5.4 AI Model Launch Just a Day After Releasing GPT-5.3 Instant
  6. Nothing Headphone (a) Launched With Adaptive ANC, Customisable Controls: Price, Specifications
  7. Granny OTT Release Date: When and Where to Watch the Village Mystery Thriller Online?
  8. Andhaka OTT Release: Where to Watch the Telugu Drama-Thriller Online?
  9. Pookie OTT Release: When and Where to Watch Vijay Antony’s Romantic Drama Online?
  10. WhatsApp Plus Paid Subscription Reportedly in Development With Additional Customisation Options, Up to 20 Pinned Chats
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.