VYPR
Unrated severityNVD Advisory· Published Jan 25, 2023· Updated Apr 4, 2025

Western Digital My Cloud OS 5 arbitrary file read and write vulnerability via ftp

CVE-2022-29844

Description

A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files. This could lead to a full NAS compromise and would give remote execution capabilities to the attacker.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Western Digital My Cloud OS 5 devices before 5.26.119 have an FTP service vulnerability allowing arbitrary file read/write and remote code execution.

Vulnerability

The FTP service in Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 contains a path traversal vulnerability that allows an unauthenticated attacker to read and write arbitrary files on the device. This affects all supported My Cloud models, including PR2100, PR4100, EX4100, EX2 Ultra, Mirror G2, DL2100, DL4100, EX2100, My Cloud, and WD Cloud [1].

Exploitation

An attacker can exploit this vulnerability over the network without any authentication or user interaction by sending specially crafted FTP commands that traverse the filesystem. The FTP service runs with elevated privileges, enabling access to sensitive system files [1].

Impact

Successful exploitation allows the attacker to read and write arbitrary files on the NAS, potentially leading to full compromise of the device. By writing malicious files (e.g., cron jobs, scripts, or configuration files), the attacker can achieve remote code execution with root privileges, giving them full control over the NAS [1].

Mitigation

Western Digital has addressed this vulnerability in firmware version 5.26.119, released on January 10, 2023. Users should update their My Cloud devices to the latest firmware immediately. No workarounds are available if patching is not possible [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.