Skip to main content

WD My Cloud web interface could give hackers the key to your files

WD PR4100 NAS review
Anthony Thurston/Digital Trends
Western Digital’s My Cloud network-attached storage (NAS) drives feature several unpatched security problems which could leave users vulnerable to attack by nefarious individuals. WD has been made aware of the flaws in the system, and the team that discovered the bugs has now made them available to the public in the hope that it encourages a quicker turnaround on a fix.

Traditionally, the playbook for revealing security issues with hardware or software is to let the manufacturer know first. That way, the company has some time to fix up the problem without it negatively affecting its business. More importantly, it means that hackers who weren’t aware of the bug don’t exploit it while it’s being fixed.

In this case, Exploitee.rs (via Engadget) who who discovered the bugs, made them public straight away due to what was described as WD’s “reputation within the community.” More specifically, Western Digital earned the Pwnie award at BlackHat Las Vegas 2016 for “Lamest Vendor Response” to bugs revealed to it in the past. By alerting the community, Exploitee hopes that users can avoid this particular drive range until WD goes ahead and fixes it.

There are actually a few bugs that were found as part of this latest investigation. Although they were specifically discovered on the My Cloud PR4100, they are expected to impact the entire My Cloud range. They are mostly to do with poorly written login scripts which could allow a hacker to bypass the certification system entirely, but others allow unauthorised file uploads, missing login requirements, and poorly implemented web interface commands.

Western Digital MyCloud Multiple Remote Root Exploits

While WD has yet to issue a response to these claims, My Cloud owners would be wise to keep their NAS drive offline for the time being and restrict it to your local network until several security fixes are released.

Editors' Recommendations

Jon Martindale
Jon Martindale is the Evergreen Coordinator for Computing, overseeing a team of writers addressing all the latest how to…
Best tools to stress test your CPU
A CPU cooler installed on a motherboard.

Running a CPU stress test tool is a great way to break in a new processor, test an overclock, see how capable your cooling is, or just make sure your PC is running as well as it should. There are a number of CPU stress tests out there, but we have a few favorites you should check out.

The goal of stress testing is to push the computer to failure. You want to see how long it takes before it becomes unstable. It's usually a good idea to run tests for at least an hour or two, though some can take longer.

Read more
One of Lenovo’s best-selling ThinkPad laptops is 45% off today
Lenovo ThinkPad X1 Carbon Gen 12 front angled view showing display and keyboard.

If you're on browsing through laptop deals for a machine that will immensely help in boosting your productivity, you may want to check out Lenovo's offer for the popular Lenovo ThinkPad X1 Carbon Gen 11. It's a powerful device so its original price is $3,319, but a 45% discount from Lenovo brings it down to a more reasonable $1,825. That's $1,494 in savings that you'll be able to spend on software and accessories, but you're going to have to proceed with the purchase right now if you want to make sure that you get it because this is a clearance sale, so there's no guarantee that stocks will still be available tomorrow.

Why you should buy the Lenovo ThinkPad X1 Carbon
The Lenovo ThinkPad X1 Carbon Gen 11 challenges the performance of the best laptops with its 13th-generation Intel Core i7 processor, integrated Intel Iris Xe Graphics, and 16GB of RAM that our guide on how much RAM do you need says is similar to what you'll find in top-tier machines. The device comes with a 14-inch touchscreen with WUXGA resolution for sharp details and bright colors, a 1TB SSD for ample storage space for your files, and Windows 11 Pro pre-installed so that you can access the more advanced capabilities of the operating system.

Read more
The world’s first 8K mini-LED monitor has arrived
The Asus ProArt PA32KCX 8K mini-LED professional monitor placed on a desk next to a workstation PC.

When it comes to the best professional-grade monitors, resolution, brightness, and color accuracy are all paramount. Asus is aiming to ace all three (and a lot more) with its newly announced ProArt PA32KCX, which is also the world’s first 8K mini-LED professional monitor.

The 8K resolution is the standout spec, of course. The monitor has a resolution of 7680 x 4320 across its 32-inch screen. One of the only other 8K monitors available that you actually buy is the Dell UltraSharp UP3218K, which came out in 2017.

Read more