VYPR
Unrated severityNVD Advisory· Published May 10, 2023· Updated Jan 24, 2025

Server Side Request Forgery Vulnerability in Western Digital My Cloud Devices

CVE-2022-29840

Description

Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback adapter was addressed in Western Digital My Cloud OS 5 devices. This could allow the URL to exploit other vulnerabilities on the local server.This issue affects My Cloud OS 5 devices before 5.26.202.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A server-side request forgery (SSRF) in WD My Cloud OS 5 before 5.26.202 allows a rogue LAN server to redirect a request to the loopback adapter, potentially exploiting other local services.

Vulnerability

A server-side request forgery (SSRF) vulnerability exists in Western Digital My Cloud OS 5 devices. A rogue server on the local network can modify its URL to point back to the loopback adapter (127.0.0.1), causing the My Cloud device to send a request to itself. This affects all My Cloud OS 5 devices prior to firmware version 5.26.202 [1].

Exploitation

An attacker must have a rogue server present on the same local network as the My Cloud device. The rogue server intercepts or serves a response that tricks the My Cloud OS into following a URL that points to the loopback interface (localhost). No authentication from the attacker is required, as the SSRF is triggered purely through network-level manipulation of the URL [1].

Impact

Successful exploitation allows the attacker to perform SSRF, potentially accessing services running on the local server that are normally only reachable via the loopback adapter. This could enable the attacker to exploit other vulnerabilities on the My Cloud device, potentially leading to further compromise such as information disclosure or unauthorized actions [1].

Mitigation

Western Digital released firmware version 5.26.202 on May 15, 2023, which addresses this vulnerability. All My Cloud OS 5 devices—including My Cloud PR2100, PR4100, EX4100, EX2 Ultra, Mirror G2, DL2100, DL4100, EX2100, My Cloud, and WD Cloud—must be updated to this version or later to mitigate the issue [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.