← Vulnerability feed

Vulnerability record · CVE-2017-17560 · published 12 December 2017

CVE-2017-17560: Western Digital MyCloud PR4100 unauthenticated file upload leads to root RCE

Westerndigital · My Cloud Pr4100 Firmware

The web administration component /web/jquery/uploader/multi_uploadify.php on Western Digital MyCloud PR4100 firmware 2.30.172 accepts multipart uploads without authentication and lets a file be written anywhere on the device file system. An attacker can therefore drop a PHP shell and execute code as root. The flaw is an improper authentication issue (CWE-287) rated CVSS 3.0 9.8 critical.

9.8 CVSS 3.0 Critical EPSS 73% · top 0.5% CWE-287 · Improper authentication
9.8CVSS 3.0 base score, v2 10.0
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload functionality that is accessible without authentication and can be used to place a file anywhere on the device's file system. This allows an attacker the ability to upload a PHP shell onto the device and obtain arbitrary code execution as root.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable upload leading to root code execution, with public exploit code and very high EPSS probability.

What it is

The web administration component /web/jquery/uploader/multi_uploadify.php on Western Digital MyCloud PR4100 firmware 2.30.172 accepts multipart uploads without authentication and lets a file be written anywhere on the device file system. An attacker can therefore drop a PHP shell and execute code as root. The flaw is an improper authentication issue (CWE-287) rated CVSS 3.0 9.8 critical.

Impact

An attacker gains arbitrary code execution as root on the device, giving full control of the NAS and any data or credentials it holds. No privileges are required beforehand.

Attack surface

Reachable over the network through the device's web administration interface via the multi_uploadify.php endpoint; the CVSS vector AV:N/AC:L/PR:N/UI:N confirms no authentication and no user interaction are needed.

Exploitation

Public exploit code exists (Exploit-DB 43356, a Metasploit module PR, and a DEF CON 25 presentation), and EPSS is 0.734 with a 0.9944 percentile, though the CVE is not listed in CISA KEV.

What to do

  • Apply the Western Digital firmware update that fixes the unauthenticated upload endpoint; if none is available for this model, retire or isolate the device.
  • Block external access to the MyCloud web administration interface and restrict it to a trusted management network.
  • Disable or remove the multi_uploadify.php upload functionality if the firmware cannot be updated.
  • Place the device behind a firewall or VPN and monitor for unexpected PHP files or writes outside expected data directories.
  • Change default credentials and audit the device for unauthorized files or accounts.

Detection

  • Monitor web server logs for POST requests to /web/jquery/uploader/multi_uploadify.php, especially from untrusted sources.
  • Alert on creation of PHP files or other executable content in web-accessible or system directories on the device.
  • Watch for unexpected outbound connections or new processes running as root on the NAS.
  • Use file integrity monitoring on the device file system to detect unauthorized writes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-17560 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-29843Westerndigital my cloud pr2100 firmware os command injection vulnerabilityA command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.…EPSS 1.2%9.8CVE-2022-29844Westerndigital my cloud pr2100 firmware relative path traversal vulnerabilityA vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read an…EPSS 36%9.8CVE-2022-22995Westerndigital my cloud pr2100 firmware link following vulnerabilityThe combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combin…EPSS 2.7%9.8CVE-2019-9950Westerndigital my cloud firmware weak password requirements vulnerabilityWestern Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR21…EPSS 2.3%8.8CVE-2019-9949Westerndigital my cloud firmware link following vulnerabilityWestern Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmware 2.31.183 are affected by a …EPSS 3.0%7.8CVE-2022-23000Westerndigital my cloud pr2100 firmware vulnerabilityThe Western Digital My Cloud Web App [https://os5.mycloud.com/] uses a weak SSLContext when attempting to configure port forwarding rules. This was e…EPSS 0.19%7.5CVE-2022-36331Westerndigital my cloud pr2100 firmware authentication bypass by spoofing vulnerabilityWestern Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an un…EPSS 0.59%5.5CVE-2023-22817Westerndigital my cloud pr2100 firmware server-side request forgery (ssrf) vulnerabilityServer-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to …EPSS 0.24%

Source: NIST National Vulnerability Database (record CVE-2017-17560), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.