CVE-2025-41273

Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to bypass authentication of the Console web application and perform actions as an authenticated user.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:waterfall-security:wf-500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:waterfall-security:wf-500:-:*:*:*:*:*:*:*

History

01 Jun 2026, 18:57

Type Values Removed Values Added
First Time Waterfall-security wf-500
Waterfall-security wf-500 Firmware
Waterfall-security
CPE cpe:2.3:h:waterfall-security:wf-500:-:*:*:*:*:*:*:*
cpe:2.3:o:waterfall-security:wf-500_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-41273 - () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-41273 - Vendor Advisory

29 May 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 12:16

Updated : 2026-06-01 18:57


NVD link : CVE-2025-41273

Mitre link : CVE-2025-41273

CVE.ORG link : CVE-2025-41273


JSON object : View

Products Affected

waterfall-security

  • wf-500_firmware
  • wf-500
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel