CVE-2025-41265
OS Command Injection in Waterfall WF-500 TX Host
Publication date: 2026-05-29
Last updated on: 2026-05-29
Assigner: Nozomi Networks Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nozomi_networks | waterfall_wf-500_tx_host | 7.9.1.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-78 | The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an OS Command Injection issue (CWE-78) found in the Administration WebUI of the Waterfall WF-500 TX Host version 7.9.1.0. It allows remote authenticated attackers to execute arbitrary operating system commands on the affected device.
How can this vulnerability impact me? :
An attacker who successfully exploits this vulnerability can execute arbitrary OS commands on the WF-500 TX Host remotely. This can lead to unauthorized control over the device, potentially compromising system integrity, confidentiality, and availability.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The provided information does not specify how the OS Command Injection vulnerability in Waterfall WF-500 TX Host affects compliance with common standards and regulations such as GDPR or HIPAA.
What immediate steps should I take to mitigate this vulnerability?
The immediate step to mitigate this vulnerability is to update the Waterfall WF-500 TX Host software to version 7.10.0.0 R2601141040, which addresses the OS Command Injection flaw.