Skip to content
September 25, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Western Digital ‘My Cloud’ Storage Devices exist secret hard-coded backdoor
  • News

Western Digital ‘My Cloud’ Storage Devices exist secret hard-coded backdoor

Do Son January 7, 2018 2 minutes read
Add Daily CyberSecurity as a preferred source on Google

In recent years, consumers are becoming increasingly interested in NAS. Private disk manufacturers have also introduced many private cloud products but failed to make enough efforts in terms of security. Recently, foreign media exposed the Western Digital My Cloud device there is a serious backdoor news. People with ulterior motives can get unrestricted root access to networked devices. Although James Bercegay disclosed the vulnerability to vendors as early as mid-2017, six months passed and Western Digital did not fix it.

According to the full details of the proof of concept it disclosed, the most troubling thing is that My Cloud has an unchangeable hard-coded backdoor credential.

Anyone can log in to Western Digital’s My Cloud service via ‘mydlinkBRionyg’, a user name with administrator privileges and ‘abc12345cba’. After logging in, attackers have plenty of opportunities to go through commands such as commands to gain shell-less shell access.

In view of this, even cut off the external network connection, Western Digital NAS device users in the same danger in the network:

Simply elaborate an HTML image and iFrame tag on your site, and then make a request to your local network’s device using a predictable hostname. In addition to seducing access to malicious web pages, there is no need for any user interactions.

It is reported that a very wide range of affected models, including:

My Cloud Gen 2, My Cloud EX2, My Cloud EX2 Ultra, My Cloud PR2100, My Cloud PR4100, My Cloud EX4, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, and My Cloud DL4100.

Brokers have exposed a Metasploit module so everyone can easily launch attacks on WD NAS devices. Finally, we can only recommend to all affected users that there be complete disconnection until manufacturers push security patches.

Reference: thehackernews

Related coverage

  • Apache Wicket Addresses Critical RCE Vulnerability (CVE-2024-36522)
  • PoC Exploit Released for Linux Kernel Privilege Escalation (CVE-2023-0386) Bug
  • Millions of Routers at Risk: CVE-2024-21833 Threatens TP-Link Devices
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Tags: 'My Cloud' Storage Devices

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intel📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-70009CVSS 9.3
    Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker...
    📅 Updated: Sep 25, 2026
  • CVE-2026-85889CVSS 10.0
    Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a...
    📅 Updated: Sep 25, 2026
  • CVE-2026-85878CVSS 9.9
    Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
    📅 Updated: Sep 25, 2026
  • CVE-2026-62379CVSS 9.8
    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts...
    📅 Updated: Sep 25, 2026
  • CVE-2026-53581CVSS 9.0
    OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20...
    📅 Updated: Sep 25, 2026
  • CVE-2026-93641CVSS 9.3
    An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient...
    📅 Updated: Sep 25, 2026
  • CVE-2026-93642CVSS 9.3
    An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient...
    📅 Updated: Sep 25, 2026
  • CVE-2026-93643CVSS 9.8
    When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document...
    📅 Updated: Sep 25, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.