Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

WD My Cloud web interface could give hackers the key to your files

Add as a preferred source on Google

Western Digital’s My Cloud network-attached storage (NAS) drives feature several unpatched security problems which could leave users vulnerable to attack by nefarious individuals. WD has been made aware of the flaws in the system, and the team that discovered the bugs has now made them available to the public in the hope that it encourages a quicker turnaround on a fix.

Traditionally, the playbook for revealing security issues with hardware or software is to let the manufacturer know first. That way, the company has some time to fix up the problem without it negatively affecting its business. More importantly, it means that hackers who weren’t aware of the bug don’t exploit it while it’s being fixed.

Recommended Videos

In this case, Exploitee.rs (via Engadget) who who discovered the bugs, made them public straight away due to what was described as WD’s “reputation within the community.” More specifically, Western Digital earned the Pwnie award at BlackHat Las Vegas 2016 for “Lamest Vendor Response” to bugs revealed to it in the past. By alerting the community, Exploitee hopes that users can avoid this particular drive range until WD goes ahead and fixes it.

There are actually a few bugs that were found as part of this latest investigation. Although they were specifically discovered on the My Cloud PR4100, they are expected to impact the entire My Cloud range. They are mostly to do with poorly written login scripts which could allow a hacker to bypass the certification system entirely, but others allow unauthorised file uploads, missing login requirements, and poorly implemented web interface commands.

Western Digital MyCloud Multiple Remote Root Exploits

While WD has yet to issue a response to these claims, My Cloud owners would be wise to keep their NAS drive offline for the time being and restrict it to your local network until several security fixes are released.

Jon Martindale
Jon Martindale covers how to guides, best-of lists, and explainers to help everyone understand the hottest new hardware and…
Microsoft’s next Surface laptops are delayed, and the pricing might sting too
Computer, Electronics, Laptop

If you've been holding out for a new Surface, you might need to hold out a little longer. According to leaker Roland Quandt, Microsoft has pushed back the launch of its upcoming Surface hardware by roughly a month, and if early pricing signals are any indication, the wait might come with some sticker shock.

What's actually coming?

Read more
How to find archived emails in Gmail and return them to your inbox
Archived emails in Gmail are easier to find than you think—once you know where Google hides them
Gmail icon on a screen.

If you’re looking to clean up your Gmail inbox, but you don’t want to delete anything permanently, then choosing the archive option is your best bet. Whenever you archive an email, it is removed from your inbox folder while still remaining accessible. Here’s how to access any emails you have archived previously, as well as how to move such messages back to your regular inbox for fast access.

Read more
Gemini Live gets a minimalist app redesign that lets you do more
Gemini Live just got easier and faster to use
google-gemini

Google is testing a new redesign for its Gemini Live experience on Android, aiming to make interactions with its AI assistant more seamless and less intrusive. According to a 9To5Google report, the update moves away from the current full-screen interface and instead integrates Gemini Live directly into the main app view, signalling a shift toward a more practical, everyday usage model.

A Shift Away From Fullscreen AI

Read more