CVE-2025-41280

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured and file compression is enabled.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:waterfall-security:wf-500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:waterfall-security:wf-500:-:*:*:*:*:*:*:*

History

01 Jun 2026, 18:56

Type Values Removed Values Added
CPE cpe:2.3:h:waterfall-security:wf-500:-:*:*:*:*:*:*:*
cpe:2.3:o:waterfall-security:wf-500_firmware:*:*:*:*:*:*:*:*
References () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-41280 - () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-41280 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Waterfall-security wf-500
Waterfall-security wf-500 Firmware
Waterfall-security

29 May 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 12:16

Updated : 2026-06-01 18:56


NVD link : CVE-2025-41280

Mitre link : CVE-2025-41280

CVE.ORG link : CVE-2025-41280


JSON object : View

Products Affected

waterfall-security

  • wf-500_firmware
  • wf-500
CWE
CWE-23

Relative Path Traversal