← Vulnerability feed

Vulnerability record · CVE-2015-7709 · published 5 October 2015

CVE-2015-7709: Western Digital Arkeia Backup Agent auth bypass leads to remote command execution

AArkeia · Western Digital Arkeia

The arkeiad daemon in the Western Digital Arkeia Backup Agent (11.0.12 and earlier) fails to enforce authentication on the ARKFS_EXEC_CMD operation, allowing crafted requests to run arbitrary commands. Because the daemon is reachable over the network and no credentials are required, any host that can reach the agent port can take over the system.

10.0 CVSS 2.0 High EPSS 79% · top 0.4% CWE-264 · Permissions and access controls
10.0CVSS 2.0 base score
79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execute arbitrary commands via a series of crafted requests involving the ARKFS_EXEC_CMD operation.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10, public exploit code and very high EPSS probability makes this an immediate patch-or-isolate priority.

What it is

The arkeiad daemon in the Western Digital Arkeia Backup Agent (11.0.12 and earlier) fails to enforce authentication on the ARKFS_EXEC_CMD operation, allowing crafted requests to run arbitrary commands. Because the daemon is reachable over the network and no credentials are required, any host that can reach the agent port can take over the system.

Impact

An unauthenticated remote attacker gains full command execution as the arkeiad service account, which typically yields complete compromise of the backup server (CVSS 2.0 base 10, C/I/A all complete).

Attack surface

Reached over the network via the arkeiad service port; the CVSS vector AV:N/AC:L/Au:N confirms no authentication and no user interaction are needed, only a series of crafted requests invoking ARKFS_EXEC_CMD.

Exploitation

Public exploit code exists (Rapid7 Metasploit module, Packet Storm, Exploit-DB) and EPSS is 0.79 (99.6th percentile), though CISA KEV does not list it.

What to do

  • Patch or upgrade Arkeia Backup Agent beyond 11.0.12; if no fixed release is available, retire or replace the product.
  • Block network access to the arkeiad service port from untrusted networks; restrict it to the backup management subnet and trusted hosts only.
  • Run the arkeiad service with a least-privilege account and isolate backup servers on a segmented management VLAN.
  • Monitor for and remove any unauthorized accounts, scheduled tasks or binaries left after suspected exploitation.

Detection

  • Alert on unexpected processes spawned by arkeiad, especially shells or command interpreters.
  • Monitor network traffic to the arkeiad port for ARKFS_EXEC_CMD operations from hosts that are not the backup management server.
  • Baseline normal arkeiad child processes and flag deviations, including outbound connections from the backup server.
  • Review arkeiad and system logs for authentication bypass patterns or repeated crafted request sequences.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-7709 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2015-7709), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.