OS Command Injection Vulnerability in Waterfall WF-500 TX and RX Hosts
CVE-2025-41275
9.3CRITICAL
What is CVE-2025-41275?
A vulnerability has been identified in the Console WebUI of Nozomi Networks' Waterfall WF-500 TX and RX hosts, where improper neutralization of special elements can allow remote unauthenticated attackers to execute arbitrary operating system commands. This could potentially compromise the integrity and security of the affected devices, exposing them to further exploitation.
Affected Version(s)
WF-500 0 <= 7.9.1.0 R2502171040
