Junglewise Threat Intelligence

CVE-2025-41280: Waterfall WF-500 RX Host path traversal in file compression handling

CVE-2025-41280 · Severity: info · CVSS 7.5 · Published 2026-05-29

Technologies: Waterfall Security Solutions WF-500 RX Host. Vendors: Waterfall Security Solutions.

Executive brief

A security vulnerability exists in the Waterfall WF-500 RX Host, a unidirectional security gateway used to protect industrial control systems. An attacker with access to the sending side of the gateway can exploit a flaw in how compressed files are handled to execute unauthorized code on the receiving side. This could allow an attacker to bypass security boundaries and gain control over the receiving host, potentially disrupting operations or accessing sensitive industrial data.

Technical details

A Relative Path Traversal (Zip Slip) vulnerability exists in the Waterfall WF-500 RX Host version 7.9.1.0 R2502171040. The flaw is classified as CWE-23 and occurs when file compression is enabled and a MySQL connector is configured. An attacker who has already gained access to the TX (Transmit) Host can craft a malicious compressed archive that, when processed by the RX (Receive) Host, writes files to arbitrary locations outside the intended directory. This path traversal can be leveraged to achieve remote code execution (RCE) on the RX Host. The attack vector is local in the context of the gateway's internal communication architecture.

Affected products

  • Waterfall Security Solutions WF-500 RX Host 7.9.1.0 R2502171040

Timeline

  • 2026-05-29: disclosed: Initial advisory publication by Nozomi Networks Labs
  • 2026-05-29: advisory: NVD record created

References

Related threats