Executive brief
A security vulnerability has been identified in the Waterfall WF-500 Unidirectional Security Gateway, a device used to protect industrial control systems by allowing data to flow in only one direction. An attacker can remotely delete critical system files without needing a username or password. This could lead to a complete shutdown of the gateway, disrupting the secure flow of data between industrial networks and corporate environments.
Technical details
A Relative Path Traversal vulnerability (CWE-23) exists within the Administration WebUI of Waterfall WF-500 TX and RX Hosts. The flaw resides in how the web interface handles file paths, allowing an attacker to use special characters (such as '../') to bypass intended directory restrictions. This vulnerability is exploitable over the network without authentication or user interaction. A successful exploit allows a remote attacker to delete arbitrary files on the host operating system, potentially leading to a denial-of-service condition or system instability. The issue is confirmed in version 7.9.1.0 R2502171040.
Affected products
- Waterfall Security Solutions WF-500 TX Host 7.9.1.0 R2502171040
- Waterfall Security Solutions WF-500 RX Host 7.9.1.0 R2502171040
Timeline
- 2026-05-29: advisory: CVE published by Nozomi Networks Labs