Junglewise Threat Intelligence

CVE-2025-41278: Waterfall WF-500 RX Host out-of-bounds read code execution

CVE-2025-41278 · Severity: info · CVSS 7.5 · Published 2026-05-29

Technologies: Waterfall Security Solutions WF-500 RX Host. Vendors: Waterfall Security Solutions.

Executive brief

A security vulnerability has been identified in the Waterfall WF-500 RX Host, a component of a unidirectional security gateway used to protect industrial control systems. An attacker who has already gained access to the transmitting (TX) side of the gateway can exploit this flaw to execute unauthorized code on the receiving (RX) side. This could allow an attacker to bypass the physical isolation provided by the hardware, potentially leading to a full compromise of the protected network.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Waterfall WF-500 RX Host version 7.10.0.0 R2601141040. The flaw is triggered when processing data sent from the TX (Transmitting) Host. While the attack vector is classified as local (AV:L) because it requires a foothold on the adjacent TX component of the gateway, successful exploitation allows for remote code execution on the RX Host. This effectively compromises the integrity of the unidirectional security gap. The vulnerability was identified by Nozomi Networks Labs.

Affected products

  • Waterfall Security Solutions WF-500 RX Host 7.10.0.0 R2601141040

Timeline

  • 2026-05-29: disclosed: Initial disclosure by Nozomi Networks Labs and NVD publication.

References

Related threats