CVE-2025-41266
CVSS Score
0.0
EPSS Score
0.7%
EPSS Percentile
72th
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 TX Host.
| CWE | CWE-78 |
| Vendor | waterfall |
| Product | wf-500 |
| Published | May 29, 2026 |
| Last Updated | May 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for waterfall wf-500
Be the first to know when new unknown vulnerabilities affecting waterfall wf-500 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Waterfall / WF-500
0 โค 7.9.1.0 R2502171040
References
Credits
Luca Borzacchiello at Nozomi Networks