Junglewise Threat Intelligence

CVE-2025-41267: Waterfall WF-500 TX Host OS command injection in Administration WebUI

CVE-2025-41267 · Severity: info · CVSS 8.5 · Published 2026-05-29

Technologies: Waterfall Security Solutions WF-500 TX Host. Vendors: Waterfall Security Solutions.

Executive brief

A vulnerability exists in the administration interface of the Waterfall WF-500 TX Host, a hardware component used for secure industrial data transfer. An authorized administrator could potentially execute unauthorized commands on the underlying system. This could lead to a complete takeover of the device, potentially disrupting industrial operations or compromising the integrity of the secure data gateway.

Technical details

An OS command injection vulnerability (CWE-78) exists in the Administration WebUI of the Waterfall WF-500 TX Host. The flaw stems from improper neutralization of special elements used in an OS command within the web management interface. A remote attacker with high-level administrative privileges can exploit this vulnerability to execute arbitrary operating system commands on the host. The vulnerability was identified in version 7.9.1.0 R2502171040. Exploitation requires network access to the WebUI and valid administrative credentials.

Affected products

  • Waterfall Security Solutions WF-500 TX Host 7.9.1.0 R2502171040

Timeline

  • 2026-05-29: disclosed: Initial disclosure by Nozomi Networks Labs
  • 2026-05-29: advisory: NVD publication date

References

Related threats