CVE-2025-41269
CVSS Score
0.0
EPSS Score
1.0%
EPSS Percentile
78th
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.
| CWE | CWE-78 |
| Vendor | waterfall |
| Product | wf-500 |
| Published | May 29, 2026 |
| Last Updated | May 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for waterfall wf-500
Be the first to know when new unknown vulnerabilities affecting waterfall wf-500 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Waterfall / WF-500
0 โค 7.9.1.0 R2502171040
References
Credits
Luca Borzacchiello at Nozomi Networks