Junglewise Threat Intelligence

CVE-2025-41277: Waterfall WF-500 OS command injection in Console WebUI

CVE-2025-41277 · Severity: info · CVSS 9.3 · Published 2026-05-29

Technologies: Waterfall Security Solutions WF-500 RX Host, Waterfall Security Solutions WF-500 TX Host. Vendors: Waterfall Security Solutions.

Executive brief

A critical vulnerability has been identified in Waterfall WF-500 unidirectional security gateways, which are used to protect industrial control systems and critical infrastructure. An attacker can remotely take full control of the device without needing a username or password. This could allow an adversary to disrupt industrial operations, manipulate data transfers, or gain a foothold in sensitive networks.

Technical details

An OS command injection vulnerability (CWE-78) exists in the Console WebUI of Waterfall WF-500 TX and RX hosts. The flaw stems from improper neutralization of special elements used in OS commands within the web management interface. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the device, leading to arbitrary command execution with the privileges of the web service. This affects version 7.9.1.0 R2502171040. Successful exploitation grants the attacker complete control over the affected host.

Affected products

  • Waterfall Security Solutions WF-500 TX Host 7.9.1.0 R2502171040
  • Waterfall Security Solutions WF-500 RX Host 7.9.1.0 R2502171040

Timeline

  • 2026-05-29: disclosed: Initial disclosure by Nozomi Networks Labs
  • 2026-05-29: advisory

References

Related threats