Executive brief
A critical vulnerability has been identified in Waterfall WF-500 TX and RX hosts, which are unidirectional security gateways used to protect industrial control systems and critical infrastructure. An attacker can remotely take full control of the device without needing any login credentials. This could lead to a complete disruption of secure data transfers, unauthorized access to sensitive industrial networks, and the ability to manipulate the device's operations.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Console WebUI of Waterfall WF-500 TX and RX hosts. The flaw stems from improper neutralization of special elements used in OS commands within the web management interface. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the WebUI, leading to arbitrary command execution with the privileges of the web service. This affects version 7.9.1.0 R2502171040. Successful exploitation grants the attacker full system access, potentially compromising the integrity of the unidirectional data diode security model.
Affected products
- Waterfall Security Solutions WF-500 TX Host 7.9.1.0 R2502171040
- Waterfall Security Solutions WF-500 RX Host 7.9.1.0 R2502171040
Timeline
- 2026-05-29: disclosed: Initial disclosure by Nozomi Networks Labs
- 2026-05-29: advisory: NVD publication date