CVE 9.3 CRITICAL

CVE-2025-41270_CVE-2025-41270

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.

AI Analysis

Remote OS command injection vulnerability in Waterfall WF-500 Console WebUI

Basic Information

ID CVE-2025-41270
Source Nozomi
Published May 29, 2026 at 10:51

Affected Product

Vendor Waterfall
Product WF-500
Version 7.9.1.0 R2502171040
Affected Versions Waterfall WF-500 0

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor Waterfall
Product WF-500
Version 7.9.1.0 R2502171040

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.