OS Command Injection Vulnerability in Waterfall WF-500 TX Host by Nozomi Networks
CVE-2025-41265
8.6HIGH
What is CVE-2025-41265?
A vulnerability exists in the Administration WebUI of the Waterfall WF-500 TX Host, where attackers with remote authenticated access can exploit improper neutralization of special elements in OS commands. This flaw permits the execution of arbitrary operating system commands, potentially leading to unauthorized control over the affected system.
Affected Version(s)
WF-500 0 <= 7.9.1.0 R2502171040
