Skip to main content

Western Digital My Cloud Multiple Vulnerabilities

Three vulnerabilities in Western Digital's popular "My Cloud" network-attached storage (NAS) devices for home or small office use have been discovered. These may allow an unauthenticated remote attacker read and write access to a device.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Three vulnerabilities in Western Digital's popular "My Cloud" network-attached storage (NAS) devices for home or small office use have been discovered. These may allow an unauthenticated remote attacker read and write access to a device.

Threat details

The first vulnerability allows an attacker to unrestricted upload access to a device. The PHP gethostbyaddr() function found on the My Cloud built-in web server allows a user to define a remote authentication server. A series of bugs in the checks performed on these servers allow an unauthorised user upload access to a device.

A hardcoded backdoor exists in the My Cloud device firmware where the login functionality would specifically look for an administration user named "mydlinkBRionyg" that would then accept the password "abc12345cba". This backdoor can then be turned into a root shell to provide root access to a device.

The final exploit describes a method for using cross-site request forgery (XSRF) to send faulty commands to perform denial-of-service (DoS) attacks.


Remediation steps

Type Step
Western Digital have reported all issues are fixed as of firmware version 2.30.172. Update can be found here.

Last edited: 17 February 2020 12:57 pm