OS Command Injection Vulnerability in Waterfall WF-500 TX and RX Hosts by Nozomi Networks
CVE-2025-41274
9.3CRITICAL
What is CVE-2025-41274?
An OS command injection vulnerability has been discovered in the Console WebUI of Nozomi Networks' Waterfall WF-500 TX and RX Hosts. This flaw, stemming from inadequate neutralization of special elements, allows remote unauthenticated attackers to execute arbitrary OS commands on affected devices, potentially leading to significant security breaches.
Affected Version(s)
WF-500 0 <= 7.9.1.0 R2502171040
