WD My Cloud DLNA Vulnerability
A vulnerability has been identified in Western Digital's MyCloud devices which allows unauthenticated local users full access to the device's contents.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
A vulnerability has been identified in Western Digital's MyCloud devices which allows unauthenticated local users full access to the device's contents.
Threat details
The vulnerability lies in the UPnP (Universal Plug 'n' Play) server which is enabled by default on all MyCloud devices. Using HTTP requests, an attacker is able to bypass any permissions, authentication or restrictions set by administrators.
Remediation steps
Last edited: 17 February 2020 12:57 pm