CVE-2025-41267

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 TX Host.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:waterfall-security:wf-500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:waterfall-security:wf-500:-:*:*:*:*:*:*:*

History

21 Jul 2026, 12:10

Type Values Removed Values Added
Summary
  • (es) Nozomi Networks Labs identificó un CWE-78: Neutralización Incorrecta de Elementos Especiales utilizados en un Comando de Sistema Operativo ('Inyección de Comandos del Sistema Operativo') en la WebUI de Administración en el Host Waterfall WF-500 TX en la versión 7.9.1.0 R2502171040 que permite a atacantes remotos autenticados ejecutar comandos arbitrarios del sistema operativo en el Host WF-500 TX.

01 Jun 2026, 18:57

Type Values Removed Values Added
References () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-41267 - () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-41267 - Vendor Advisory
CPE cpe:2.3:h:waterfall-security:wf-500:-:*:*:*:*:*:*:*
cpe:2.3:o:waterfall-security:wf-500_firmware:*:*:*:*:*:*:*:*
First Time Waterfall-security wf-500
Waterfall-security wf-500 Firmware
Waterfall-security
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

29 May 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 12:16

Updated : 2026-07-21 12:10


NVD link : CVE-2025-41267

Mitre link : CVE-2025-41267

CVE.ORG link : CVE-2025-41267


JSON object : View

Products Affected

waterfall-security

  • wf-500_firmware
  • wf-500
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')