WDMyClous Security Vulnerabilities

http://gulftech.org/advisories/WDMyCloud%20Multiple%20Vulnerabilities/125

Looks like there is no /usr/local/modules/cgi/nas_sharing.cgi file on the PR4100, but it seems like the easiest way to foil someone wiping your NAS using that exploit (for now) would be to change the hostname of the mycloud device to something other than the default. Locking your device down to LAN access only with the exception of a few services is advisable in any case.

1 Like