Junglewise Threat Intelligence

CVE-2025-41265: Waterfall WF-500 TX Host OS command injection in Administration WebUI

CVE-2025-41265 · Severity: info · CVSS 8.6 · Published 2026-05-29

Technologies: Waterfall Security Solutions WF-500 TX Host. Vendors: Waterfall Security Solutions.

Executive brief

A security vulnerability exists in the Waterfall WF-500 TX Host, a hardware component used to protect industrial control systems and critical infrastructure. An attacker with administrative access to the device's web management interface can execute unauthorized commands on the underlying operating system. This could lead to a complete takeover of the device, potentially disrupting the secure data flow between protected industrial networks and external systems.

Technical details

An OS command injection vulnerability (CWE-78) exists in the Administration WebUI of the Waterfall WF-500 TX Host. The flaw stems from improper neutralization of special elements used in OS commands within the web management interface. A remote attacker with high privileges (authenticated) can exploit this by sending crafted requests to the WebUI, leading to arbitrary command execution on the host operating system. The vulnerability was identified in version 7.9.1.0 R2502171040. Successful exploitation grants the attacker full control over the TX Host component.

Affected products

  • Waterfall Security Solutions WF-500 TX Host 7.9.1.0 R2502171040

Timeline

  • 2026-05-29: advisory: Vulnerability disclosed by Nozomi Networks Labs and published in NVD.

References

Related threats