Junglewise Threat Intelligence

CVE-2025-41272: Waterfall WF-500 OS command injection in Console WebUI

CVE-2025-41272 · Severity: info · CVSS 9.3 · Published 2026-05-29

Technologies: Waterfall Security Solutions WF-500 RX Host, Waterfall Security Solutions WF-500 TX Host. Vendors: Waterfall Security Solutions.

Executive brief

A critical security vulnerability has been identified in the management interface of Waterfall WF-500 unidirectional security gateways. These devices are used to protect industrial control systems by ensuring data only flows in one direction. An attacker could exploit this flaw to take complete control of the device remotely without needing a password, potentially disrupting critical infrastructure monitoring or compromising the integrity of the protected network.

Technical details

An OS command injection vulnerability (CWE-78) exists in the Console WebUI of Waterfall WF-500 TX and RX Hosts. The flaw stems from improper neutralization of special elements used in an OS command within the web management interface. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the WebUI, leading to arbitrary command execution with the privileges of the web service. This allows for complete takeover of the affected host. The vulnerability is confirmed in version 7.9.1.0 R2502171040.

Affected products

  • Waterfall Security Solutions WF-500 TX Host 7.9.1.0 R2502171040
  • Waterfall Security Solutions WF-500 RX Host 7.9.1.0 R2502171040

Timeline

  • 2026-05-29: disclosed: Vulnerability disclosed by Nozomi Networks Labs
  • 2026-05-29: advisory: NVD record published

References

Related threats