Vulnerability record · CVE-2017-17560 · published 12 December 2017
CVE-2017-17560: Western Digital MyCloud PR4100 unauthenticated file upload leads to root RCE
Westerndigital · My Cloud Pr4100 Firmware
The web administration component /web/jquery/uploader/multi_uploadify.php on Western Digital MyCloud PR4100 firmware 2.30.172 accepts multipart uploads without authentication and lets a file be written anywhere on the device file system. An attacker can therefore drop a PHP shell and execute code as root. The flaw is an improper authentication issue (CWE-287) rated CVSS 3.0 9.8 critical.
Description
An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload functionality that is accessible without authentication and can be used to place a file anywhere on the device's file system. This allows an attacker the ability to upload a PHP shell onto the device and obtain arbitrary code execution as root.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable upload leading to root code execution, with public exploit code and very high EPSS probability.
What it is
The web administration component /web/jquery/uploader/multi_uploadify.php on Western Digital MyCloud PR4100 firmware 2.30.172 accepts multipart uploads without authentication and lets a file be written anywhere on the device file system. An attacker can therefore drop a PHP shell and execute code as root. The flaw is an improper authentication issue (CWE-287) rated CVSS 3.0 9.8 critical.
Impact
An attacker gains arbitrary code execution as root on the device, giving full control of the NAS and any data or credentials it holds. No privileges are required beforehand.
Attack surface
Reachable over the network through the device's web administration interface via the multi_uploadify.php endpoint; the CVSS vector AV:N/AC:L/PR:N/UI:N confirms no authentication and no user interaction are needed.
Exploitation
Public exploit code exists (Exploit-DB 43356, a Metasploit module PR, and a DEF CON 25 presentation), and EPSS is 0.734 with a 0.9944 percentile, though the CVE is not listed in CISA KEV.
What to do
- Apply the Western Digital firmware update that fixes the unauthenticated upload endpoint; if none is available for this model, retire or isolate the device.
- Block external access to the MyCloud web administration interface and restrict it to a trusted management network.
- Disable or remove the multi_uploadify.php upload functionality if the firmware cannot be updated.
- Place the device behind a firewall or VPN and monitor for unexpected PHP files or writes outside expected data directories.
- Change default credentials and audit the device for unauthorized files or accounts.
Detection
- Monitor web server logs for POST requests to /web/jquery/uploader/multi_uploadify.php, especially from untrusted sources.
- Alert on creation of PHP files or other executable content in web-accessible or system directories on the device.
- Watch for unexpected outbound connections or new processes running as root on the NAS.
- Use file integrity monitoring on the device file system to detect unauthorized writes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://download.exploitee.rs/file/generic/Exploiteers-DEFCON25.pdf | ExploitThird Party Advisory |
| https://github.com/rapid7/metasploit-framework/pull/9248 | Third Party Advisory |
| https://www.exploit-db.com/exploits/43356/ | ExploitThird Party AdvisoryVDB Entry |
| https://download.exploitee.rs/file/generic/Exploiteers-DEFCON25.pdf | ExploitThird Party Advisory |
| https://github.com/rapid7/metasploit-framework/pull/9248 | Third Party Advisory |
| https://www.exploit-db.com/exploits/43356/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-17560 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-17560), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.