Executive brief
A critical security flaw has been identified in Waterfall WF-500 Unidirectional Security Gateways, which are used to protect industrial control systems by ensuring data only flows in one direction. An attacker can remotely take full control of the device's management interface without needing a username or password. This could allow an adversary to disrupt industrial operations, modify device configurations, or gain a foothold in the network.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Console WebUI of Waterfall WF-500 TX and RX hosts. The flaw stems from improper neutralization of special elements used in OS commands within the web management interface. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the device, leading to arbitrary command execution at the operating system level. The vulnerability is present in version 7.9.1.0 R2502171040. Successful exploitation grants the attacker full system compromise (High Confidentiality, Integrity, and Availability impact) without requiring user interaction.
Affected products
- Waterfall Security Solutions WF-500 TX Host 7.9.1.0 R2502171040
- Waterfall Security Solutions WF-500 RX Host 7.9.1.0 R2502171040
Timeline
- 2026-05-29: disclosed: Initial disclosure by Nozomi Networks Labs
- 2026-05-29: advisory: NVD record published