Western Digital urges customers to patch NAS drive backdoor
Security researcher discovers hard-coded flaw in storage appliances
Western Digital has urged customers to update the firmware on their NAS appliances, after a security researcher discovered a number of security issues including a hard-coded backdoor that allows anyone to gain access to the devices.
GulfTech researcher James Bercegay discovered the vulnerability, which allows attackers to log into an affected NAS device using a pre-set username and password that cannot be changed or modified.
The affected models are: MyCloud, MyCloudMirror, My Cloud Gen 2, My Cloud PR2100, My Cloud PR4100, My Cloud EX2 Ultra, My Cloud EX2, My Cloud EX4, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100 and My Cloud DL4100.
Bercegay also discovered several other vulnerabilities, including command injection, cross-site request forgery and unrestricted file upload flaws. Interestingly, he noted that the backdoor and file upload issued perfectly matched flaws found in the D-Link DNS-320L ShareCenter, a rival NAS device, making it possible that Western Digital licensed the (flawed) code from D-Link in order to build its NAS appliance.
Western Digital told IT Pro that Bercegay had already notified it of the flaws, and that the issue was addressed in the v2.30.172 firmware update. A spokesperson urged customers to update to the latest version of the firmware in order to avoid being affected.
"As a reminder, we urge customers to ensure the firmware on their products is always up to date; enabling automatic updates is recommended. We also urge you to implement sound data protection practices such as regular data backups and password protection, including to secure your router when you use a personal cloud or network-attached storage device," they said.
"Western Digital works continuously to improve the capability and security of our products, including with the security research community to address issues they may uncover. We encourage responsible disclosure by customers and researchers to ensure our customers are protected while we address valid vulnerabilities."
Staying ahead of the game in the world of data
Create successful marketing campaigns by understanding your customers betterDownload now
Remote working 2020: Advantages and challenges
Discover how to overcome remote working challengesDownload now
Keep your data available with snapshot technology
Synology’s solution to your data protection problemDownload now
After the lockdown - reinventing the way your business works
Your guide to ensuring business continuity, no matter the crisisDownload now