OS Command Injection Vulnerability in Waterfall WF-500 TX and RX Hosts by Nozomi Networks
CVE-2025-41276
9.3CRITICAL
What is CVE-2025-41276?
A vulnerability discovered in Nozomi Networks' Waterfall WF-500 TX and RX Hosts allows remote, unauthenticated attackers to execute arbitrary operating system commands via the Console WebUI. This issue arises from a failure to properly neutralize special elements used in OS commands, classified as CWE-78. Exploiting this vulnerability can compromise the integrity of the device and lead to unauthorized access.
Affected Version(s)
WF-500 0 <= 7.9.1.0 R2502171040
