CVE-2025-41265

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 TX Host.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:waterfall-security:wf-500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:waterfall-security:wf-500:-:*:*:*:*:*:*:*

History

21 Jul 2026, 12:10

Type Values Removed Values Added
Summary
  • (es) Nozomi Networks Labs identificó un CWE-78: Neutralización Inadecuada de Elementos Especiales utilizados en un Comando del Sistema Operativo ('Inyección de Comandos del Sistema Operativo') en la Interfaz de Usuario Web de Administración (WebUI) en el Host Waterfall WF-500 TX en la versión 7.9.1.0 R2502171040 que permite a atacantes remotos autenticados ejecutar comandos arbitrarios del sistema operativo en el Host WF-500 TX.

01 Jun 2026, 18:58

Type Values Removed Values Added
References () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-41265 - () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-41265 - Vendor Advisory
CPE cpe:2.3:h:waterfall-security:wf-500:-:*:*:*:*:*:*:*
cpe:2.3:o:waterfall-security:wf-500_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
First Time Waterfall-security wf-500
Waterfall-security wf-500 Firmware
Waterfall-security

29 May 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 12:16

Updated : 2026-07-21 12:10


NVD link : CVE-2025-41265

Mitre link : CVE-2025-41265

CVE.ORG link : CVE-2025-41265


JSON object : View

Products Affected

waterfall-security

  • wf-500_firmware
  • wf-500
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')