Junglewise Threat Intelligence

CVE-2025-41273: Waterfall WF-500 authentication bypass in Console WebUI

CVE-2025-41273 · Severity: info · CVSS 9.3 · Published 2026-05-29

Technologies: Waterfall Security Solutions WF-500 RX Host, Waterfall Security Solutions WF-500 TX Host. Vendors: Waterfall Security Solutions.

Executive brief

A security vulnerability has been identified in the Waterfall WF-500 Unidirectional Security Gateway, a device used to protect industrial control systems by ensuring data only flows in one direction. An attacker can bypass the login screen of the device's management interface without needing a username or password. This could allow an unauthorized person to change device settings or disrupt the monitoring of critical infrastructure.

Technical details

An authentication bypass vulnerability (CWE-288) exists in the Console WebUI of Waterfall WF-500 TX and RX hosts. The flaw involves the use of an alternate path or channel that allows an attacker to circumvent standard authentication mechanisms. A remote, unauthenticated attacker can exploit this vulnerability over the network to gain access to the web application with the privileges of an authenticated user. This allows for full unauthorized management of the affected host. The vulnerability is confirmed in version 7.9.1.0 R2502171040.

Affected products

  • Waterfall Security Solutions WF-500 TX Host 7.9.1.0 R2502171040
  • Waterfall Security Solutions WF-500 RX Host 7.9.1.0 R2502171040

Timeline

  • 2026-05-29: disclosed: Initial disclosure by Nozomi Networks Labs and NVD publication.

References

Related threats