Executive brief
A critical vulnerability has been identified in the Waterfall WF-500 TX and RX hosts, which are hardware components used to securely bridge industrial networks. An attacker can remotely take full control of these devices without needing a username or password. This could lead to a complete disruption of industrial operations or unauthorized access to sensitive monitoring data.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Console WebUI of Waterfall WF-500 TX and RX Hosts. The flaw stems from improper neutralization of special elements used in OS commands within the web interface. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the device, resulting in arbitrary code execution with the privileges of the web service. The vulnerability is present in version 7.9.1.0 R2502171040.
Affected products
- Waterfall Security Solutions WF-500 TX Host 7.9.1.0 R2502171040
- Waterfall Security Solutions WF-500 RX Host 7.9.1.0 R2502171040
Timeline
- 2026-05-29: disclosed: Initial disclosure by Nozomi Networks Labs
- 2026-05-29: advisory: CVE published in NVD dataset