Executive brief
A security vulnerability has been identified in the Waterfall WF-500 RX Host, a component of a unidirectional security gateway used to protect industrial control systems. An attacker who has already gained access to the transmitting (TX) side of the gateway can exploit this flaw to execute unauthorized code on the receiving (RX) side. This could allow an attacker to bypass the physical isolation provided by the hardware, potentially leading to a full compromise of the protected network.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Waterfall WF-500 RX Host version 7.10.0.0 R2601141040. The flaw is triggered when processing data sent from the TX (Transmitting) Host. While the attack vector is classified as local (AV:L) because it requires a foothold on the adjacent TX component of the gateway, successful exploitation allows for remote code execution on the RX Host. This effectively compromises the integrity of the unidirectional security gap. The vulnerability was identified by Nozomi Networks Labs.
Affected products
- Waterfall Security Solutions WF-500 RX Host 7.10.0.0 R2601141040
Timeline
- 2026-05-29: disclosed: Initial disclosure by Nozomi Networks Labs and NVD publication.