Western Digital My Cloud OS 5 arbitrary file read and write vulnerability via ftp
Description
A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files. This could lead to a full NAS compromise and would give remote execution capabilities to the attacker.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Western Digital My Cloud OS 5 devices before 5.26.119 have an FTP service vulnerability allowing arbitrary file read/write and remote code execution.
Vulnerability
The FTP service in Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 contains a path traversal vulnerability that allows an unauthenticated attacker to read and write arbitrary files on the device. This affects all supported My Cloud models, including PR2100, PR4100, EX4100, EX2 Ultra, Mirror G2, DL2100, DL4100, EX2100, My Cloud, and WD Cloud [1].
Exploitation
An attacker can exploit this vulnerability over the network without any authentication or user interaction by sending specially crafted FTP commands that traverse the filesystem. The FTP service runs with elevated privileges, enabling access to sensitive system files [1].
Impact
Successful exploitation allows the attacker to read and write arbitrary files on the NAS, potentially leading to full compromise of the device. By writing malicious files (e.g., cron jobs, scripts, or configuration files), the attacker can achieve remote code execution with root privileges, giving them full control over the NAS [1].
Mitigation
Western Digital has addressed this vulnerability in firmware version 5.26.119, released on January 10, 2023. Users should update their My Cloud devices to the latest firmware immediately. No workarounds are available if patching is not possible [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <5.26.119
- Western Digital/My Cloudv5Range: My Cloud OS 5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.