Junglewise Threat Intelligence

CVE-2025-41281: Waterfall WF-500 RX Host OS command injection in MySQL connector

CVE-2025-41281 · Severity: info · CVSS 7.5 · Published 2026-05-29

Technologies: Waterfall Security Solutions WF-500 RX Host. Vendors: Waterfall Security Solutions.

Executive brief

A security vulnerability has been identified in the Waterfall WF-500 RX Host, a component used in industrial data diode solutions to securely transfer data between networks. An attacker who has already gained access to the sending side (TX Host) of the device can execute unauthorized commands on the receiving side (RX Host) if a specific database connector is used. This could allow an attacker to bypass the physical isolation provided by the data diode, potentially compromising sensitive receiving networks or disrupting operations.

Technical details

An OS command injection vulnerability (CWE-78) exists in the Waterfall WF-500 RX Host version 7.9.1.0 R2502171040. The flaw is triggered when a MySQL connector is configured, failing to properly neutralize special elements used in OS commands. An attacker with existing access to the TX (Transmit) Host can exploit this to execute arbitrary code on the RX (Receive) Host. While the attack vector is classified as local (AV:L) in the CVSS metrics, it represents a significant cross-domain security breach in the context of unidirectional security gateways.

Affected products

  • Waterfall Security Solutions WF-500 RX Host 7.9.1.0 R2502171040

Timeline

  • 2026-05-29: advisory: Advisory published by Nozomi Networks Labs and NVD

References

Related threats