Junglewise Threat Intelligence

CVE-2025-41271: Waterfall WF-500 path traversal in Console WebUI

CVE-2025-41271 · Severity: info · CVSS 8.7 · Published 2026-05-29

Technologies: Waterfall Security Solutions WF-500 RX Host, Waterfall Security Solutions WF-500 TX Host. Vendors: Waterfall Security Solutions.

Executive brief

A security vulnerability has been identified in Waterfall WF-500 unidirectional security gateways, which are used to protect industrial control systems by allowing data to flow in only one direction. An attacker can exploit this flaw to remotely access and read sensitive files from the device's management interface without needing a username or password. This could lead to the exposure of configuration details or other confidential system information, potentially aiding further attacks against the industrial network.

Technical details

A Relative Path Traversal vulnerability (CWE-23) exists in the Console WebUI of Waterfall WF-500 TX and RX Hosts running version 7.9.1.0 R2502171040. The flaw is located within the web management interface and stems from insufficient validation of user-supplied input used to construct file paths. A remote, unauthenticated attacker can exploit this by sending specially crafted HTTP requests containing path traversal sequences (e.g., ../) to access files outside of the intended web root directory. Successful exploitation allows for the unauthorized retrieval of arbitrary system files, though it does not inherently grant write access or remote code execution.

Affected products

  • Waterfall Security Solutions WF-500 TX Host 7.9.1.0 R2502171040
  • Waterfall Security Solutions WF-500 RX Host 7.9.1.0 R2502171040

Timeline

  • 2026-05-29: disclosed: Initial disclosure by Nozomi Networks Labs
  • 2026-05-29: advisory: NVD publication date

References

Related threats