Executive brief
A security vulnerability has been identified in the Waterfall WF-500 RX Host, a hardware component used for secure data transfer between industrial networks. An attacker with administrative access to the device's web management interface can execute unauthorized commands on the underlying operating system. This could lead to a complete takeover of the device, potentially disrupting industrial data flows or compromising the integrity of the secure gateway.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Administration WebUI of the Waterfall WF-500 RX Host. The flaw stems from improper neutralization of special elements within user-supplied input used to construct system commands. A remote attacker with high privileges (authenticated) can exploit this via the network to execute arbitrary operating system commands with the privileges of the web service. The vulnerability is confirmed in version 7.9.1.0 R2502171040. Successful exploitation results in a full compromise of the host's confidentiality, integrity, and availability.
Affected products
- Waterfall Security Solutions WF-500 RX Host 7.9.1.0 R2502171040
Timeline
- 2026-05-29: disclosed: Initial disclosure by Nozomi Networks Labs
- 2026-05-29: advisory: NVD publication date