Vulnerability record · CVE-2019-9951 · published 24 April 2019
CVE-2019-9951: Western digital my cloud mirror gen 2 firmware unrestricted file upload vulnerability
Western Digital · My Cloud Mirror Gen 2 Firmware
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an unauthenticated file upload vulnerability. The page web/jquery/uploader/uploadify.php can be accessed without any credentials, and allows uploading arbitrary files to any location on the attached storage.
Description
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an unauthenticated file upload vulnerability. The page web/jquery/uploader/uploadify.php can be accessed without any credentials, and allows uploading arbitrary files to any location on the attached storage.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bnbdr.github.io/posts/wd/ | |
| https://community.wd.com/t/new-release-my-cloud-firmware-versions-2-31-174-3-26-19/235932 | Release NotesThird Party Advisory |
| https://github.com/bnbdr/wd-rce/ | |
| https://support.wdc.com/downloads.aspx?g=2702&lang=en | Third Party Advisory |
| https://bnbdr.github.io/posts/wd/ | |
| https://community.wd.com/t/new-release-my-cloud-firmware-versions-2-31-174-3-26-19/235932 | Release NotesThird Party Advisory |
| https://github.com/bnbdr/wd-rce/ | |
| https://support.wdc.com/downloads.aspx?g=2702&lang=en | Third Party Advisory |
Track CVE-2019-9951 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-9951), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.