EIP-2026-101492

PRE-CVE

WDMyCloud < 2.30.165 - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101492. PoCs published by GulfTech Security.

AI-analyzed exploit summary This is a detailed writeup describing multiple vulnerabilities in WDMyCloud devices, including an unrestricted file upload vulnerability and a hardcoded backdoor account. The document provides code analysis, exploitation details, and proof-of-concept information.

Description

WDMyCloud < 2.30.165 - Multiple Vulnerabilities

Exploits (1)

exploitdb WRITEUP
by GulfTech Security · textremotehardware
https://www.exploit-db.com/exploits/43435

This is a detailed writeup describing multiple vulnerabilities in WDMyCloud devices, including an unrestricted file upload vulnerability and a hardcoded backdoor account. The document provides code analysis, exploitation details, and proof-of-concept information.

Classification
Writeup 100%
Attack Type
Rce | Auth Bypass | Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Western Digital MyCloud <= 2.30.165
No auth needed
Prerequisites: Network access to the WDMyCloud device · Knowledge of the vulnerabilities described
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026