CVE-2025-41278
Out-of-bounds Read in Waterfall WF-500 RX Host
Publication date: 2026-05-29
Last updated on: 2026-05-29
Assigner: Nozomi Networks Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nozomi_networks | waterfall_wf-500_rx_host | 7.10.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-125 | The product reads data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an out-of-bounds read (CWE-125) found in the Waterfall WF-500 RX Host software version 7.10.0.0 R2601141040. It allows attackers who have access to the TX Host to execute code on the RX Host.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized code execution on the RX Host by attackers with access to the TX Host. This could compromise the affected system's integrity, potentially allowing attackers to control or disrupt its operations.
What immediate steps should I take to mitigate this vulnerability?
The recommended immediate step to mitigate this vulnerability is to update the Waterfall WF-500 RX Host software to version v7.10.1.0.