Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Western Digital

Western Digital Vendor Cyber Rating & Cyber Score

westerndigital.com

At Western Digital, our vision is to unleash the power and value of data. For decades, we have been at the forefront of storage innovation, which fuels our mission to be the market leader in data storage, delivering solutions for now and the future. We are committed to providing scalable, sustainable technology for the world’s hyperscalers, enterprises, and cloud providers, and delivering cutting-edge innovation that will drive the next generation of AI-driven data workloads. All that we do is powered by our people, who are united in a common purpose of creating solutions that move the world forward. Learn more at www.westerndigital.com.


Western Digital A.I CyberSecurity Scoring

Western Digital
Company Information
Website:https://www.westerndigital.com
Employees number:22,591
Number of followers:805,765
NAICS:3341
Industry Type:Computer Hardware Manufacturing
Homepage:westerndigital.com
Western Digital Risk Score (AI oriented)
Between 750 and 799
logo
Western DigitalComputer Hardware Manufacturing
Updated:
03/04/2026
773/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Western Digital Global Score (TPRM)
xxxx
logo
Western DigitalComputer Hardware Manufacturing
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Western Digital
Western DigitalFair
Current Score
773Baa (FAIR)
01000
4 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
791Before Incident
MAY 2026
788Before Incident
APRIL 2026
782Before Incident
MARCH 2026
781Before Incident
FEBRUARY 2026
770Before Incident
JANUARY 2026
770Before Incident
DECEMBER 2025
754Before Incident
NOVEMBER 2025
753Before Incident
OCTOBER 2025
752Before Incident
SEPTEMBER 2025
753Before Incident
Vulnerability
23 Sep 2025Western Digital
Western Digital

Western Digital My Cloud NAS Critical OS Command Injection Vulnerability (CVE-2025-30247)

750After Incident
CRITICAL-3
WES5892358093025
Western Digital disclosed a critical OS command injection vulnerability (CVE-2025-30247) in multiple My Cloud NAS models, including PR2100, PR4100, EX4100, EX2 Ultra, Mirror Gen 2, DL2100, EX2100, DL4100, and WDBCTLxxxxxx-10. The flaw allows remote attackers to execute arbitrary system commands via crafted HTTP POST requests, potentially leading to unauthorized file access, modification, deletion, user enumeration, or binary execution. While primarily affecting small businesses, home offices, and consumers, exploitation could enable data theft, botnet recruitment, proxy misuse, or ransomware deployment. Two models (DL4100 and DL2100) are end-of-support (EoS), leaving them unpatched. Users are urged to update to firmware 5.31.108 immediately or disconnect devices until patched. Automatic updates were rolled out on September 23, 2025, but manual updates are also available. Failure to patch risks severe compromise of stored data, including potential lateral movement into connected networks or ransomware attacks targeting backups and sensitive files.
INCIDENT DETAILS -
TYPE
VulnerabilityOS Command Injection
IMPACT
Potential unauthorized file accessModificationDeletionUser enumerationMy Cloud PR2100My Cloud PR4100My Cloud EX4100My Cloud EX2 UltraMy Cloud Mirror Gen 2My Cloud DL2100My Cloud EX2100My Cloud DL4100My Cloud WDBCTLxxxxxx-10Potential unauthorized configuration changesBinary executionLoss of cloud access if taken offlineBrand Reputation Impact: Potential reputational damage due to vulnerability in consumer-facing product
DATA BREACH
Potential: Stored files (personal/cloud data)User credentialsConfiguration dataPotentially high (personal files, backups, media)Data Exfiltration: Possible (historical exploits on NAS devices include data harvesting)Personally Identifiable Information: Possible (if stored on device)
AUGUST 2025
752Before Incident
JULY 2025
751Before Incident
JUNE 2025
752Before Incident
Vulnerability
16 Jun 2025Western Digital
Western Digital

Critical Remote Code Execution Vulnerability in Western Digital My Cloud NAS Devices (CVE-2025-30247)

749After Incident
CRITICAL-3
WES5632056093025
Western Digital disclosed a critical remote code execution (RCE) vulnerability (CVE-2025-30247) in the firmware of its My Cloud NAS devices, affecting models like My Cloud PR2100, PR4100, EX2 Ultra, and others running firmware versions prior to v5.31.108. The flaw, an OS command injection in the user interface, allows unauthenticated attackers to execute arbitrary system commands via a crafted HTTP POST request without user interaction.A successful exploit grants full system control, enabling attackers to access, encrypt, delete, or modify all stored data, including backups, project files, and sensitive documents. The compromised device could also serve as a launchpad for lateral movement within the same network, risking further breaches of connected systems.While no in-the-wild exploitation has been reported, the vulnerability poses a severe risk to home and small business users relying on these devices for storage and backups. Western Digital urged immediate firmware updates, with automatic updates already applied to connected devices. Failure to patch could lead to data loss, ransomware deployment, or network-wide compromise if exploited by threat actors.
INCIDENT DETAILS -
TYPE
VulnerabilityRemote Code Execution (RCE)
IMPACT
Potential full access to stored data (if exploited)My Cloud PR2100My Cloud PR4100My Cloud EX2 UltraMy Cloud EX4100My Cloud Mirror Gen 2My Cloud EX2100My Cloud DL2100My Cloud DL4100My Cloud WDBCTLxxxxxx-10Potential data encryption, deletion, or modification; lateral movement risk to other network systemsPotential reputational damage if exploited in the wild
DATA BREACH
Potential: All data stored on affected NAS devices (documents, backups, project files, etc.)Potentially high (depends on user-stored content)Possible if exploitedPossible unauthorized encryption by attackersPossible (if stored by users)
MAY 2023
750Before Incident
Breach
01 May 2023Western Digital
Western Digital

Western Digital Data Breach

711After Incident
CRITICAL-39
WES04621023
Customers of Western Digital are being informed of a data breach that exposed their private information. It stopped a number of its services in response to the incident. The business acknowledged that various systems had been compromised by an unauthorised individual. To confirm that threat actors stole sensitive personal information in the March attack, the organisation is notifying customers of data breaches through letters. According to the corporation, they are collaborating with law enforcement to examine the full scope of the occurrence with the help of renowned forensic and security specialists.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data theft
IMPACT
Data Compromised: Sensitive personal information
DATA BREACH
Type Of Data Compromised: Sensitive personal information
APRIL 2023
817Before Incident
Ransomware
01 Apr 2023Western Digital
Western Digital

Western Digital Ransomware Attack

749After Incident
HIGH-68
WES233828523
Western Digital experienced a ransomware assault, and as a result, it had to suspend some of its services. The company acknowledged that various systems had been compromised by an unauthorised individual. My Cloud, My Cloud Home, My Cloud Home Duo, My Cloud OS5, SanDisk ibi, and SanDisk Ixpand Wireless Charger were all impacted by a service outage encountered by Western Digital. Customer names, shipping and billing addresses, phone numbers, and email addresses were among the information that was exposed. Customer passwords that had been hashed or salted as well as a portion of their credit card details were found in the hacked database, the company noted. Customers of Western Digital are advised to exercise caution when responding to unsolicited mailings that request personal information from them or direct them to a website that does the same. Customers are advised against opening attachments or clicking on links in shady communications.
INCIDENT DETAILS -
TYPE
Ransomware
IMPACT
Customer namesShipping and billing addressesPhone numbersEmail addressesHashed or salted passwordsPartial credit card detailsMy CloudMy Cloud HomeMy Cloud Home DuoMy Cloud OS5SanDisk ibiSanDisk Ixpand Wireless Charger
DATA BREACH
Customer namesShipping and billing addressesPhone numbersEmail addressesHashed or salted passwordsPartial credit card details

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Western Digital ?
?
What was Western Digital's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Western Digital's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Western Digital's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Western Digital's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Western Digital's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Western Digital's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Western Digital's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Western Digital's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Western Digital's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Western Digital's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Western Digital's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Western Digital's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Western Digital ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Western Digital's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Western Digital Cyber Scoring History | Rankiteo