CVE 9.3 CRITICAL

CVE-2025-41273_CVE-2025-41273

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to bypass authentication of the Console web application and perform actions as an authenticated user.

AI Analysis

Authentication Bypass Vulnerability in Waterfall WF-500 Console WebUI

Basic Information

ID CVE-2025-41273
Source Nozomi
Published May 29, 2026 at 10:53

Affected Product

Vendor Waterfall
Product WF-500
Version 7.9.1.0 R2502171040
Affected Versions Waterfall WF-500 0

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor Waterfall
Product WF-500
Version 7.9.1.0 R2502171040

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.