Junglewise Threat Intelligence

CVE-2025-41266: Waterfall WF-500 TX Host OS command injection in Administration WebUI

CVE-2025-41266 · Severity: info · CVSS 8.6 · Published 2026-05-29

Technologies: Waterfall Security Solutions WF-500 TX Host. Vendors: Waterfall Security Solutions.

Executive brief

A vulnerability exists in the administration interface of the Waterfall WF-500 TX Host, a hardware component used for secure industrial data transfer. An attacker with administrative credentials can exploit this flaw to take full control of the device by executing unauthorized system commands. This could lead to a complete disruption of secure data flows or unauthorized access to the underlying operating system of the security gateway.

Technical details

An OS command injection vulnerability (CWE-78) exists in the Administration WebUI of the Waterfall WF-500 TX Host. The flaw stems from improper neutralization of special elements within user-supplied input used to construct system commands. A remote attacker with high privileges (authenticated) can exploit this via the network to execute arbitrary operating system commands on the host. The vulnerability was identified in version 7.9.1.0 R2502171040. Successful exploitation results in a total loss of confidentiality, integrity, and availability for the affected host.

Affected products

  • Waterfall Security Solutions WF-500 TX Host 7.9.1.0 R2502171040

Timeline

  • 2026-05-29: disclosed: Initial disclosure by Nozomi Networks Labs
  • 2026-05-29: advisory: NVD record published

References

Related threats