Executive brief
A critical vulnerability has been identified in the Waterfall WF-500 Unidirectional Security Gateway, a device used to protect industrial control systems by ensuring data only flows in one direction. An attacker can remotely take full control of the device's management interface without needing a username or password. This could allow an adversary to disrupt industrial operations, modify system configurations, or gain a foothold in sensitive infrastructure networks.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Console WebUI of Waterfall WF-500 TX and RX hosts. The flaw stems from improper neutralization of special elements within user-supplied input processed by the web management interface. A remote, unauthenticated attacker can exploit this by sending specially crafted network requests to the device. Successful exploitation grants the attacker the ability to execute arbitrary operating system commands with high privileges, leading to a complete compromise of the host's integrity, availability, and confidentiality.
Affected products
- Waterfall Security Solutions WF-500 TX Host 7.9.1.0 R2502171040
- Waterfall Security Solutions WF-500 RX Host 7.9.1.0 R2502171040
Timeline
- 2026-05-29: disclosed: Initial disclosure by Nozomi Networks Labs
- 2026-05-29: advisory: NVD record published